Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
40.029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | 0.47% | — | Linux KernelAI | 24/9/2026 | 25/9/2026 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and assigns gc_ctx.len only on the success tail. The caller storage is svcdata->clcred, which… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Minimp3AI | 24/9/2026 | 29/9/2026 | minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field. | |
| Pendiente de análisis | Crítica (9.2) | 0.27% | — | Openstack ZaqarAI | 24/9/2026 | 26/9/2026 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read,… | |
| Pendiente de análisis | Crítica (9.2) | 0.33% | — | Portswigger Burp Suite DastAI | 24/9/2026 | 24/9/2026 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. | |
| Aplazada | Crítica (9.8) | 0.31% | — | MpackAI | 24/9/2026 | 25/9/2026 | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Geelen Mcp-remoteAI | 24/9/2026 | 29/9/2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | |
| Aplazada | Crítica (9.1) | 0.35% | — | Mcp-remoteAI | 24/9/2026 | 25/9/2026 | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header | |
| Aplazada | Crítica (10) | 0.32% | — | Rejetto HFSAI | 24/9/2026 | 24/9/2026 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of… | |
| Aplazada | Crítica (10) | 0.78% | — | Hfs2AI | 24/9/2026 | 29/9/2026 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Dashbit Nimble ZTAAI | 24/9/2026 | 24/9/2026 | Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected. verify_token/2 in lib/nimble_zta/cloudflare.ex… | |
| Pendiente de análisis | Crítica (9.9) | 0.40% | — | VelociraptorAI | 24/9/2026 | 25/9/2026 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt… | |
| Aplazada | Crítica (9.8) | 2.9% | 💥 Exploit | Visualcomposer Visual Composer Website BuilderAI | 24/9/2026 | 24/9/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Deltaww DiaenergieAI | 24/9/2026 | 24/9/2026 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. | |
| Aplazada | Crítica (9.8) | 0.35% | — | Deltaww DiaenergieAI | 24/9/2026 | 24/9/2026 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022. | |
| Aplazada | Crítica (9.3) | 0.65% | — | Dlink Dir-825AI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely. | |
| Aplazada | Crítica (9.2) | 0.41% | — | SignozAI | 24/9/2026 | 24/9/2026 | SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both… | |
| Aplazada | Crítica (9.8) | 0.39% | — | PaytiumAI | 24/9/2026 | 24/9/2026 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on… | |
| Analizada | Crítica (9.9) | 0.55% | — | Gitlab | 23/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially… | |
| Analizada | Crítica (9.9) | 0.44% | — | Gitlab | 23/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted… | |
| Aplazada | Crítica (9.3) | 0.62% | — | Laravel MediableAI | 23/9/2026 | 24/9/2026 | Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default… | |
| Analizada | Crítica (9.8) | 0.45% | — | IBM Concert | 23/9/2026 | 29/9/2026 | IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 1.4% | — | IBM Concert | 23/9/2026 | 28/9/2026 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application. | |
| En análisis | Crítica (9.2) | 0.24% | — | RabbitmqAI | 23/9/2026 | 29/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forge the JWKS response, which leads the broker to accept… | |
| En análisis | Crítica (9.1) | 0.25% | — | RabbitmqAI | 23/9/2026 | 29/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 →… | |
| Pendiente de análisis | Crítica (9.4) | 0.61% | — | WP ToolkitAICpanelAI | 23/9/2026 | 24/9/2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. |