Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

11.339 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.4)0.33%—Nvidia Tensorrt-llm14/7/202622/9/2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
AnalizadaAlta (8.2)0.63%—Sensiolabs Symfony14/7/202621/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap, i-regexp restriction, or bounded…
AnalizadaAlta (8.3)0.67%—Sensiolabs Symfony14/7/202615/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with…
AnalizadaAlta (7.6)0.49%—Sensiolabs Symfony14/7/202615/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an…
AnalizadaBaja (2.3)0.34%—Sensiolabs Symfony14/7/202616/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers…
AnalizadaBaja (2.3)0.35%—Sensiolabs Symfony14/7/202615/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored…
AnalizadaMedia (5.3)0.48%—Os4ed Opensis14/7/202614/7/2026
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
Pendiente de análisisCrítica (9.2)0.43%—Siemens Simatic S7-1500 Software Controller 5370AISiemens Simatic S7-1500 Software Controller 5570AI14/7/202629/9/2026
Existe un problema de denegación de servicio en los controladores 5370/5570. Esta vulnerabilidad podría permitir potencialmente a un usuario remoto cargar un proyecto no válido, haciendo que el dispositivo entre en una falla mayor no recuperable (MNRF).
AplazadaCrítica (10)0.50%—Siemens Opcenter XAI14/7/202615/7/2026
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user…
AplazadaMedia (6)0.27%—Siemens Simatic S7-plcsim AdvancedAI14/7/202615/7/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a…
Pendiente de análisisAlta (8.9)0.47%—Redhat Openshift GitopsAIArgoproj Argo CDAI14/7/202611/8/2026
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes…
AplazadaAlta (8.5)0.16%—Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+614/7/20265/10/2026
Se ha identificado una vulnerabilidad en COMOS V10.4.5 (Todas las versiones menor que la versión V10.4.5.0.2), COMOS V10.6 (Todas las versiones menor que la versión V10.6.1), Designcenter NX (Todas las versiones menor que la versión V2512.7000), Simcenter 3D (Todas las versiones menor que la versión V2512.7000),…
AplazadaAlta (7.1)0.17%—Opensuse TumbleweedAISuricataAI14/7/202615/7/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1.
Pendiente de análisisAlta (7.5)0.42%—Openshift Incluster-checksAI13/7/202614/7/2026
A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes.
AplazadaMedia (5.4)0.29%—Wpexperts License Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
AplazadaAlta (7.1)0.25%—Stmcan Rt-theme 18AIStmcan Rt18-extensionsAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
AplazadaCrítica (9.8)0.56%—Rt-theme 18 ExtensionsAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
AplazadaAlta (8.1)0.56%—Stmcan Rt-theme 18 ExtensionsAI13/7/202613/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
AplazadaMedia (6.5)0.22%—Netrr Author BOX WP LensAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.
AplazadaAlta (7.1)0.25%—Codemenschen Gift VouchersAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.
AplazadaMedia (6.5)0.33%—Codemenschen Gift VoucherAI13/7/202613/7/2026
Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouchers: from n/a through <= 4.6.9.
AplazadaAlta (7.1)0.25%—Hupe13 Extensions FOR Leaflet MAPAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.
AplazadaAlta (8.2)0.48%—Openstack IronicAI10/7/202610/7/2026
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
AplazadaMedia (5.5)0.41%—Openstack IronicAI10/7/202610/7/2026
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
AplazadaCrítica (9.4)0.17%—Citrix XapiAICitrix XenserverAI9/7/202610/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…