Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
5119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.43% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.19% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.8) | 0.43% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Ninguna (0) | 0.34% | — | Mediawiki | 1/7/2026 | 13/7/2026 | Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9. | |
| Analizada | Ninguna (0) | 0.48% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with program files includes/UrlShortenerUtils.Php. | |
| Analizada | Ninguna (0) | 0.29% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue. | |
| Analizada | Ninguna (0) | 0.29% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from… | |
| Analizada | Ninguna (0) | 0.27% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0. | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX y BlueField contienen una vulnerabilidad en la interfaz de comandos donde un usuario local con acceso a la función virtual (VF) puede causar una escritura fuera de límites mediante una entrada manipulada. Un exploit exitoso de esta vulnerabilidad puede conducir a la ejecución de código arbitrario en el… | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX y BlueField contienen una vulnerabilidad en la interfaz de comandos donde un usuario local con acceso a la función virtual (VF) puede causar una escritura fuera de límites mediante una entrada especialmente diseñada. Un exploit exitoso de esta vulnerabilidad puede conducir a la ejecución de código… | |
| Analizada | Media (6.9) | 0.23% | — | Mediawiki Cargo | 1/7/2026 | 6/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1. | |
| Analizada | Media (6.9) | 0.13% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3. | |
| Aplazada | Alta (8.1) | 0.60% | — | Najeebmedia Frontend File ManagerAI | 28/6/2026 | 29/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase… | |
| Aplazada | Media (6.5) | 0.47% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 26/6/2026 | 26/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin… | |
| Aplazada | Alta (7.5) | 0.41% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers. | |
| Aplazada | Media (5.4) | 0.23% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with… | |
| Pendiente de análisis | Alta (7.1) | 0.88% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In… | |
| Pendiente de análisis | Alta (7.1) | 0.58% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately… | |
| Pendiente de análisis | Alta (7.1) | 0.64% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then… | |
| Pendiente de análisis | Alta (7.6) | 0.42% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds… | |
| Aplazada | Media (4.8) | 0.31% | — | Hashgraph GuardianAI | 18/6/2026 | 14/7/2026 | Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the… | |
| Analizada | Media (5.2) | 0.60% | — | Eclipse 4diac Forte | 18/6/2026 | 2/7/2026 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free). | |
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35. | |
| Aplazada | Media (6) | 0.24% | — | Shenzhen Liandian Communication Technology V380 IP CameraAI | 18/6/2026 | 22/6/2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data. | |
| Pendiente de análisis | Crítica (9.3) | 1.3% | 💥 PoC | Nvidia Spatial Intelligence LABAI | 17/6/2026 | 14/7/2026 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can… |