Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
23.894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.37% | — | Fogproject | 21/7/2026 | 7/8/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without sanitization, and the Host Management Inventory page renders all… | |
| Analizada | Alta (7.3) | 0.20% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. | |
| Analizada | Media (6) | 0.24% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | |
| Analizada | Baja (1.8) | 0.25% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. | |
| Analizada | Media (6.9) | 0.31% | — | Mobyproject Buildkit | 21/7/2026 | 30/7/2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. | |
| Analizada | Media (4.2) | 0.10% | — | Sparkle-project Sparkle | 21/7/2026 | 5/8/2026 | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach… | |
| Analizada | Media (6.1) | 0.34% | — | Sparkle-project Sparkle | 21/7/2026 | 5/8/2026 | Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks deeper in the relative path.… | |
| Analizada | Media (5.6) | 0.41% | — | Mobyproject Buildkit | 20/7/2026 | 5/8/2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process. | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Examination SystemAI | 19/7/2026 | 22/7/2026 | A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.5) | 0.43% | — | Excon Project Excon | 17/7/2026 | 29/7/2026 | Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes… | |
| Analizada | Alta (8.2) | 0.59% | — | Asyncssh Project Asyncssh | 17/7/2026 | 30/7/2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the OpenSSH-compatible AuthorizedKeysFile %u token in asyncssh/config.py, asyncssh/connection.py, asyncssh/auth_keys.py, and… | |
| Aplazada | Crítica (9.3) | 0.32% | — | ZebradAIHalo2 GadgetsAIZcash PrimitivesAIOrchardproject OrchardAI+1 | 17/7/2026 | 17/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying… | |
| Aplazada | Media (5.3) | 0.32% | — | Mojo JWTAI | 17/7/2026 | 20/7/2026 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of matching leading… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital BED Management SystemAI | 17/7/2026 | 21/7/2026 | A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Aplazada | Media (5.1) | 0.32% | — | Teraterm Project Ttssh2AI | 17/7/2026 | 17/7/2026 | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory… | |
| Aplazada | Media (5.1) | 0.32% | — | Teraterm Project Tera TermAI | 17/7/2026 | 17/7/2026 | Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be… | |
| Analizada | Alta (8.9) | 0.55% | — | Argoproj Argo Workflows | 16/7/2026 | 30/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of… | |
| Aplazada | Media (5.3) | 0.26% | — | Janssen Project Jans Auth ServerAI | 16/7/2026 | 16/7/2026 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and AuthzRequestService.processRequestObject() does… | |
| Analizada | Alta (7.6) | 0.23% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins… | |
| Analizada | Alta (7.6) | 0.39% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session… | |
| Analizada | Alta (7.1) | 0.53% | — | Lfprojects MCP Python SDK | 15/7/2026 | 17/7/2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only… | |
| Analizada | Alta (8.7) | 0.61% | — | Argoproj Argo CD | 15/7/2026 | 20/7/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by… | |
| Analizada | Media (6.5) | 0.52% | — | Argoproj Argo CD | 15/7/2026 | 20/7/2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because HideSecretData(target, live, ...) does not fully sanitize… | |
| Analizada | Alta (8.8) | 0.42% | — | Zephyrproject Zephyr | 15/7/2026 | 17/8/2026 | The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (OA) SPI mode by copying device-supplied 64-byte data chunks into a fixed static buffer ctx->buf of size CONFIG_ETH_ADIN2111_BUFFER_SIZE (default 1524 bytes). In… | |
| Aplazada | Alta (7.7) | 0.39% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 15/7/2026 | 16/7/2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a… |