Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
40.029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | ZimbraAI | 25/9/2026 | 29/9/2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. | |
| En análisis | Crítica (9.8) | 0.42% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs… | |
| Pendiente de análisis | Crítica (9.3) | 0.16% | — | KittyAI | 25/9/2026 | 29/9/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user's shell, because color_control() in kitty/window.py answers a query for… | |
| Analizada | Crítica (9.8) | 0.44% | — | Apache Qpid Broker-j | 25/9/2026 | 5/10/2026 | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version… | |
| Aplazada | Crítica (9.1) | 0.37% | 💥 PoC | Booking-wp-plugin BooklyAI | 25/9/2026 | 26/9/2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the… | |
| Aplazada | Crítica (9.1) | 0.39% | 💥 PoC | Cusrev Customer Reviews FOR WoocommerceAI | 25/9/2026 | 25/9/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete… | |
| Aplazada | Crítica (9.8) | 0.53% | 💥 PoC | Automation WEB PlatformAI | 25/9/2026 | 25/9/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 26/9/2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 25/9/2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison… | |
| Aplazada | Crítica (9.8) | 0.24% | — | IO Socket SSL SelfcertificateAI | 24/9/2026 | 25/9/2026 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run… | |
| Aplazada | Crítica (9.2) | 0.19% | — | Botslab G980hAI | 24/9/2026 | 25/9/2026 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Omni C20AI | 24/9/2026 | 24/9/2026 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| Aplazada | Crítica (9) | 0.68% | — | — | 24/9/2026 | 24/9/2026 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process. | |
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security… | |
| Aplazada | Crítica (9.8) | 0.57% | 💥 PoC | Honeywell Pd45 Industrial PrinterAI | 24/9/2026 | 24/9/2026 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to… | |
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Aplazada | Crítica (9.3) | 0.20% | — | DbhubAI | 24/9/2026 | 30/9/2026 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The HTTP server attempts to protect browser-origin access by… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Http4s-scala-xmlAI | 24/9/2026 | 30/9/2026 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the… | |
| Aplazada | Crítica (10) | 1.2% | 💥 PoC | DecepticonAI | 24/9/2026 | 30/9/2026 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own… | |
| Aplazada | Crítica (9.3) | 0.27% | — | IXO BlockchainAI | 24/9/2026 | 30/9/2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included… | |
| Recibida | Crítica (9.8) | 0.50% | — | Linux KernelAI | 24/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len <= off. A malicious RDMA client can… | |
| Pendiente de análisis | Crítica (9.8) | 0.45% | — | QuickjsAI | 24/9/2026 | 29/9/2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | |
| Aplazada | Crítica (9.1) | 0.39% | — | TermixAI | 24/9/2026 | 29/9/2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store attacker-controlled domain and email values through PATCH /users/acme-ssl-settings and trigger their interpolation into a certbot shell… | |
| Aplazada | Crítica (9.9) | 0.62% | — | DokployAI | 24/9/2026 | 24/9/2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An… | |
| Recibida | Crítica (9.1) | 0.47% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero passes the range check, and xdr_inline_decode(stream, 0)… |