Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.56%—WP Mail GatewayAI2/5/202617/6/2026
The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and…
AnalizadaCrítica (9.3)4.3%—Synway SMG Gateway Management Software30/4/20267/10/2026
El Software de Gestión de Pasarelas Synway SMG contiene una vulnerabilidad de inyección de comandos del sistema operativo en el endpoint de configuración RADIUS en /en/9-2radius.php donde el parámetro POST radius_address se divide y se interpola directamente en un comando sed sin sanitización. Un atacante remoto no…
Pendiente de análisisCrítica (9.3)0.42%—Amazon OPS WheelAIAmazon API GatewayAIAmazon CognitoAI24/4/202617/6/2026
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User…
Pendiente de análisisCrítica (9.3)0.67%—Intrado 911 Emergency GatewayAI23/4/202617/6/2026
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory.
AnalizadaMedia (5.3)0.57%—OpentelemetryOpentelemetry.apiOpentelemetry.extensions.propagators23/4/202617/6/2026
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can…
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaMedia (5.3)0.34%—Oracle Goldengate21/4/202617/6/2026
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access…
AplazadaMedia (5.1)0.53%—Navigate Content Management SystemAI21/4/202617/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript…
AplazadaAlta (8.7)0.57%—Openfind MailgatesAIOpenfind MailauditAI16/4/202617/6/2026
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.
AplazadaCrítica (9.3)0.98%—Openfind MailgatesAIOpenfind MailauditAI16/4/202617/6/2026
MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
AplazadaBaja (2)0.33%—DbgateAI13/4/202617/6/2026
A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The…
AplazadaBaja (2.1)0.34%—DbgateAI13/4/202617/6/2026
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the…
AnalizadaMedia (5.3)0.59%—Danielgatis Rembg10/4/202617/6/2026
Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted request with a malicious model_path parameter, an attacker can force the server to…
AnalizadaAlta (7.5)0.22%—Vmware Spring Cloud Gateway10/4/202617/6/2026
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not…
Pendiente de análisisAlta (8.8)0.19%—Gatewaygeo MapserverAI9/4/202617/6/2026
A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.
AplazadaMedia (5.3)0.29%—Ipospays Gateways WCAI8/4/202624/7/2026
Vulnerabilidad por falta de autorización en iPOSPays iPOSpays Gateways WC ipospays-gateways-wc permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a iPOSpays Gateways WC: desde n/a hasta <= 1.3.7.
AnalizadaAlta (8.8)0.27%—Gatech Computing FOR Good's Basic Laboratory Information System5/4/202624/7/2026
C4G Basic Laboratory Information System 3.4 contiene múltiples vulnerabilidades de inyección SQL que permiten a atacantes no autenticados ejecutar comandos SQL arbitrarios inyectando código malicioso a través del parámetro site. Los atacantes pueden enviar solicitudes GET al endpoint users_select.php con cargas útiles…
AnalizadaAlta (8.5)0.72%—Netgate Amiti Antivirus4/4/202621/7/2026
Netgate AMITI Antivirus compilación 23.0.305 contiene una vulnerabilidad de ruta de servicio sin comillas en los servicios AmitiAvSrv y AmitiAntivirusHealth que permite a los atacantes locales escalar privilegios. Los atacantes pueden colocar un ejecutable malicioso en la ruta de servicio sin comillas y activar el…
AnalizadaAlta (8.5)0.61%—Netgate Registry Cleaner4/4/202621/7/2026
NETGATE Registry Cleaner build 16.0.205 contiene una vulnerabilidad de ruta de servicio sin comillas en el servicio NGRegClnSrv que permite a atacantes locales escalar privilegios explotando la ruta del binario del servicio. Los atacantes pueden colocar un ejecutable malicioso en la ruta sin comillas y activar el…
AplazadaAlta (8.2)0.19%—DbgateAI2/4/202624/7/2026
DbGate es un gestor de bases de datos multiplataforma. Desde la versión 7.0.0 hasta antes de la versión 7.1.5, existe una vulnerabilidad de XSS almacenado en DbGate porque las cadenas de iconos SVG controladas por el atacante se renderizan como HTML sin procesar sin sanitización. En la interfaz de usuario web, esto…
AnalizadaAlta (7.8)0.35%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.
AnalizadaAlta (7.8)0.43%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
AnalizadaMedia (6.3)0.19%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
AnalizadaAlta (7.7)0.35%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
AnalizadaAlta (7.7)0.19%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.