Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

14.251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.9)0.16%—Cisco Secure EmailAI2/9/20262/9/2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An…
Pendiente de análisisMedia (5.9)0.16%—Cisco Secure EmailAI2/9/20262/9/2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An…
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AplazadaAlta (7.1)0.57%—Tencent Ai-infra-guardAI2/9/202624/9/2026
Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled…
AplazadaMedia (5.4)0.14%—Simple Membership Mailchimp IntegrationAI2/9/20263/9/2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is…
AplazadaMedia (6.8)0.43%—Aioseo ALL IN ONE SEOAI2/9/20263/9/2026
The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post.
AplazadaMedia (5.3)0.30%—KimaiAI2/9/20262/9/2026
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended…
AplazadaMedia (5.3)0.25%—KimaiAI2/9/20262/9/2026
Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches an existing team; because the endpoints…
AplazadaMedia (5.3)0.24%—KimaiAI2/9/20262/9/2026
Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission checks by sending POST requests to team…
AplazadaMedia (5.3)0.29%—KimaiAI2/9/20262/9/2026
Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin permission, the…
AplazadaMedia (5.3)0.33%—KimaiAI2/9/20264/9/2026
Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing authorization controls.
AplazadaBaja (1.9)0.21%—Airasia Move APPAI2/9/20262/9/2026
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The…
AplazadaMedia (6.9)0.40%—Axllent MailpitAI2/9/202610/9/2026
Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check…
AnalizadaAlta (7.5)0.58%—Kamailio1/9/202615/9/2026
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
AnalizadaAlta (7.5)0.58%—Kamailio1/9/20264/9/2026
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
En análisisCrítica (9.8)0.37%—Openai Codex DesktopAIGITAI1/9/20262/9/2026
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an…
En análisisAlta (7.3)0.11%—Openai Codex CLIAIOpenai Codex DesktopAIGit-scm GITAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an…
En análisisAlta (8.8)0.30%—Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI1/9/20262/9/2026
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex…
En análisisAlta (7.3)0.11%—Openai Codex DesktopAI1/9/20263/9/2026
OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can…
AplazadaBaja (2.1)0.32%—Xinhu Rainrock RockoaAI1/9/20261/9/2026
A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation of the argument Value can lead to sql injection. The attack may be performed from remote. The exploit has been…
AplazadaBaja (2.1)0.32%—Xinhu Rainrock RockoaAI1/9/20261/9/2026
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the…
Pendiente de análisisMedia (5.3)0.21%—CA Security DomainAI1/9/202623/9/2026
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
AplazadaBaja (3.5)0.29%—PhpmailerAIWallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled…
AplazadaAlta (7.1)0.25%—Tailored ToolsAI31/8/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
AplazadaAlta (7.1)0.25%—Email EssentialsAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.