Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.82% | 💥 PoC | Vmware Spring Cloud Config | 7/5/2026 | 15/7/2026 | Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13… | |
| Modificada | Alta (7.5) | 0.48% | — | Vmware Spring Cloud Config | 7/5/2026 | 15/7/2026 | When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support… | |
| Analizada | Alta (7.8) | 0.17% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | |
| Analizada | Media (6.6) | 0.24% | — | Oracle Cloud Native Environment Command Line Interface | 6/5/2026 | 17/6/2026 | Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a… | |
| Analizada | Media (6.1) | 0.20% | — | Oracle Cloud Infrastructure CLI | 6/5/2026 | 17/6/2026 | Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with network access to compromise Oracle OCI CLI. Successful attacks of this vulnerability can result in Oracle OCI CLI allowing… | |
| Analizada | Crítica (9.4) | 0.84% | — | Fit2cloud Sqlbot | 5/5/2026 | 24/7/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from… | |
| Aplazada | Media (5.5) | 0.65% | — | Ruoyi Vue-proAIIocoder Yudao-cloudAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 2.4% | — | Jdcloud JdcosAI | 3/5/2026 | 17/6/2026 | A flaw has been found in JD Cloud JDCOS 4.5.1.r4518. This vulnerability affects the function set_iptv_info of the file /jdcap of the component Service Interface. Executing a manipulation of the argument vid can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and… | |
| Aplazada | Baja (2.1) | 0.38% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.41% | — | Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.65% | — | Yunaiv Yudao CloudAI | 3/5/2026 | 17/6/2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Iocoder Yudao-cloudAI | 3/5/2026 | 17/6/2026 | A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoViewDataServiceImpl.java. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (6.4) | 0.35% | — | Quantumcloud Simple Link DirectoryAI | 2/5/2026 | 17/6/2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it… | |
| Analizada | Media (5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 1/5/2026 | 17/6/2026 | Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,… | |
| Aplazada | Alta (7.8) | 0.16% | — | Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI | 29/4/2026 | 17/6/2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. | |
| Aplazada | Alta (7.8) | 0.16% | — | Acronis Devicelock DLPAIAcronis Cyber Protect Cloud AgentAI | 29/4/2026 | 17/6/2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183. | |
| Aplazada | Media (5.5) | 0.61% | — | Williamcloudqi Matlab-mcp-serverAI | 28/4/2026 | 17/6/2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lead to path… | |
| Aplazada | Media (5.5) | 0.51% | — | Tencentcloud Cloudbase-mcpAI | 28/4/2026 | 24/7/2026 | A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Baja (2.2) | 0.32% | — | CloudflareAI | 24/4/2026 | 17/6/2026 | @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare Worker to follow HTTP redirects to… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Aplazada | Baja (2.1) | 0.49% | — | Soniccloudorg Sonic-serverAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Baja (2.1) | 0.36% | — | Kodcloud KodexplorerAI | 19/4/2026 | 17/6/2026 | A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2) | 0.40% | — | Kodcloud KodexplorerAI | 19/4/2026 | 17/6/2026 | A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the… | |
| Aplazada | Media (6.9) | 0.65% | — | Kodcloud KodexplorerAI | 19/4/2026 | 17/6/2026 | A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted… | |
| Aplazada | Media (5.5) | 0.72% | — | Kodcloud KodexplorerAI | 19/4/2026 | 17/6/2026 | A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit… |