Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
11.335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.14% | — | Xenproject OxenstoredAI | 9/7/2026 | 9/7/2026 | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota. | |
| Pendiente de análisis | Alta (8.6) | 0.62% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This… | |
| Pendiente de análisis | Media (6.3) | 0.23% | — | Siemens Cpci85AISiemens Sicore Base SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious… | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by… | |
| Modificada | Media (6.5) | 0.48% | — | Redhat Openshift AI | 8/7/2026 | 30/9/2026 | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a… | |
| Analizada | Crítica (9.4) | 0.30% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) | |
| Analizada | Media (6.5) | 0.29% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | |
| Analizada | Alta (7.5) | 0.62% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. | |
| Analizada | Alta (7.5) | 0.16% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. | |
| Analizada | Media (6.5) | 0.18% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. | |
| Analizada | Media (5.4) | 0.18% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. | |
| Analizada | Media (5.4) | 0.25% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. | |
| Analizada | Media (5.4) | 0.25% | — | Openbsd Openssh | 8/7/2026 | 9/7/2026 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. | |
| Analizada | Alta (8.8) | 0.53% | — | Opensuse Libzypp | 2/7/2026 | 7/7/2026 | A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root. | |
| Pendiente de análisis | Crítica (10) | 0.66% | — | Opensuse OBSAIOpensuse TAR SCMAI | 2/7/2026 | 2/7/2026 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services | |
| Aplazada | Crítica (9.8) | 0.61% | — | TR7 Cyber Defense INC Waf-aspAI | 2/7/2026 | 2/7/2026 | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | |
| Aplazada | Media (5.4) | 0.23% | — | TR7 Cyber Defense INC Waf-aspAI | 2/7/2026 | 2/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | |
| Aplazada | Media (4.6) | 0.23% | — | TR7 Cyber Defense INC WEB Application FirewallAI | 2/7/2026 | 2/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117. | |
| Modificada | Media (6.2) | 0.20% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit | 29/6/2026 | 28/9/2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.… | |
| Modificada | Alta (8.8) | 0.55% | — | Redhat Openshift DEV Spaces | 29/6/2026 | 15/7/2026 | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an… | |
| Analizada | Alta (8.8) | 0.60% | — | Opensuse Libzypp | 29/6/2026 | 30/6/2026 | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation. | |
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Aplazada | Baja (2.9) | 0.59% | — | DocumensoAI | 29/6/2026 | 29/6/2026 | A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google OAuth Login. The manipulation results in improper authentication. It is possible to launch the attack… | |
| Analizada | Media (4.9) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only… |