Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
–

5119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.43%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (7.8)0.19%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.8)0.43%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaNinguna (0)0.34%—Mediawiki1/7/202613/7/2026
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
AnalizadaNinguna (0)0.48%—Mediawiki1/7/20269/7/2026
Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with program files includes/UrlShortenerUtils.Php.
AnalizadaNinguna (0)0.29%—Mediawiki1/7/20269/7/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.
AnalizadaNinguna (0)0.29%—Mediawiki1/7/20269/7/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from…
AnalizadaNinguna (0)0.27%—Mediawiki1/7/20269/7/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.
Pendiente de análisisCrítica (9)0.37%—Nvidia ConnectxAINvidia BluefieldAI1/7/20266/10/2026
NVIDIA ConnectX y BlueField contienen una vulnerabilidad en la interfaz de comandos donde un usuario local con acceso a la función virtual (VF) puede causar una escritura fuera de límites mediante una entrada manipulada. Un exploit exitoso de esta vulnerabilidad puede conducir a la ejecución de código arbitrario en el…
Pendiente de análisisCrítica (9)0.37%—Nvidia ConnectxAINvidia BluefieldAI1/7/20266/10/2026
NVIDIA ConnectX y BlueField contienen una vulnerabilidad en la interfaz de comandos donde un usuario local con acceso a la función virtual (VF) puede causar una escritura fuera de límites mediante una entrada especialmente diseñada. Un exploit exitoso de esta vulnerabilidad puede conducir a la ejecución de código…
AnalizadaMedia (6.9)0.23%—Mediawiki Cargo1/7/20266/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS. This issue affects Mediawiki - Cargo Extension: from * before 3.9.1.
AnalizadaMedia (6.9)0.13%—Mediawiki1/7/20269/7/2026
Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.
AplazadaAlta (8.1)0.60%—Najeebmedia Frontend File ManagerAI28/6/202629/6/2026
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase…
AplazadaMedia (6.5)0.47%💥 PoCNajeebmedia Frontend File ManagerAI26/6/202626/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin…
AplazadaAlta (7.5)0.41%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.
AplazadaMedia (5.4)0.23%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with…
Pendiente de análisisAlta (7.1)0.88%—Aomedia LibaomAI19/6/20266/10/2026
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In…
Pendiente de análisisAlta (7.1)0.58%—Aomedia LibaomAI19/6/20266/10/2026
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately…
Pendiente de análisisAlta (7.1)0.64%—Aomedia LibaomAI19/6/20266/10/2026
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then…
Pendiente de análisisAlta (7.6)0.42%—Aomedia LibaomAI19/6/20266/10/2026
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds…
AplazadaMedia (4.8)0.31%—Hashgraph GuardianAI18/6/202614/7/2026
Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the…
AnalizadaMedia (5.2)0.60%—Eclipse 4diac Forte18/6/20262/7/2026
In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).
AplazadaAlta (8.5)0.36%—Davidlingren Media Library AssistantAI18/6/202618/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.
AplazadaMedia (6)0.24%—Shenzhen Liandian Communication Technology V380 IP CameraAI18/6/202622/6/2026
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.
Pendiente de análisisCrítica (9.3)1.3%💥 PoCNvidia Spatial Intelligence LABAI17/6/202614/7/2026
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can…