Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
40.034 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.51% | — | Moodle SocialwallAI | 23/9/2026 | 24/9/2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator… | |
| Aplazada | Crítica (9.3) | 0.65% | — | LightllmAI | 23/9/2026 | 23/9/2026 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to… | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. | |
| Pendiente de análisis | Crítica (10) | 0.39% | — | SuneditorAI | 23/9/2026 | 24/9/2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders… | |
| Analizada | Crítica (9.1) | 0.36% | — | Apache Tomcat Native | 23/9/2026 | 6/10/2026 | Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0… | |
| Pendiente de análisis | Crítica (9.9) | 2.9% | — | Zoho Manageengine Opmanager MSPAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. | |
| Pendiente de análisis | Crítica (9.1) | 0.31% | 💥 PoC | Apache TomcatAI | 23/9/2026 | 23/9/2026 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache TomcatAI | 23/9/2026 | 23/9/2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache TomcatAI | 23/9/2026 | 30/9/2026 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time… | |
| Pendiente de análisis | Crítica (9.8) | 0.42% | — | Apache BuildstreamAI | 23/9/2026 | 23/9/2026 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of… | |
| Aplazada | Crítica (9) | 0.19% | — | WP Oauth ServerAI | 23/9/2026 | 24/9/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and… | |
| Aplazada | Crítica (9) | 0.26% | — | Yahman Add-onsAI | 23/9/2026 | 23/9/2026 | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled. | |
| Aplazada | Crítica (9.3) | 0.58% | — | Fast Fac1203r Gigabit EditionAI | 23/9/2026 | 23/9/2026 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The… | |
| Analizada | Crítica (9.9) | 0.54% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | |
| Analizada | Crítica (9.8) | 0.51% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. | |
| Pendiente de análisis | Crítica (9.1) | 0.25% | — | MCP Toolbox-sdk-pythonAI | 22/9/2026 | 23/9/2026 | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its… | |
| En análisis | Crítica (9.1) | 0.38% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management. | |
| En análisis | Crítica (9.1) | 0.35% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints. | |
| Pendiente de análisis | Crítica (9.6) | 0.30% | — | IBM ConcertAI | 22/9/2026 | 24/9/2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions. | |
| Analizada | Crítica (9.9) | 0.45% | — | IBM Datastage ON Cloud PAK FOR Data | 22/9/2026 | 6/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Crítica (9.3) | 0.68% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Apache Http ServerAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users. | |
| Aplazada | Crítica (9.1) | 0.34% | — | OpencodeAI | 22/9/2026 | 24/9/2026 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload. |