Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 0.41% | — | Stackideas Easydiscuss | 6/2/2026 | 17/6/2026 | Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure | |
| Analizada | Media (6.5) | 0.35% | — | Tanium Discover | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Discover. | |
| Analizada | Media (6.3) | 0.28% | — | Tanium Discover | 5/2/2026 | 17/6/2026 | Tanium addressed an improper input validation vulnerability in Discover. | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP… | |
| Aplazada | Alta (7.5) | 0.42% | — | Cisco Telepresence Collaboration EndpointAICisco RoomosAI | 4/2/2026 | 17/6/2026 | A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received… | |
| Analizada | Media (4.8) | 0.21% | — | Cisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not… | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Meeting Management | 4/2/2026 | 17/6/2026 | A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the… | |
| Aplazada | Media (4) | 0.16% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 4/2/2026 | 17/6/2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. | |
| Aplazada | Baja (2.7) | 0.30% | — | Wikimedia DiscussiontoolsAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation DiscussionTools.This issue affects DiscussionTools: from * before 1.43.4, 1.44.1. | |
| Aplazada | Alta (8.8) | 0.48% | — | Wikimedia MediawikiAIWikimedia DiscussiontoolsAI | 30/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extension: 1.44, 1.43. | |
| Analizada | Media (6.5) | 0.30% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensitive information in staff action logs that should be restricted to administrators only. The exposed information includes webhook payload URLs and secrets, API key details,… | |
| Analizada | Media (6.9) | 0.28% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restricted resources (private topics, categories, posts, or hidden tags) were redirecting users to URLs containing the resource slug, even when the user didn't have access to… | |
| Analizada | Media (6.5) | 0.26% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, site admin can… | |
| Analizada | Media (5.1) | 0.19% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched in versions 3.5.4, 2025.11.2,… | |
| Analizada | Alta (7.1) | 0.26% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site, including sensitive content such as user… | |
| Analizada | Media (6.5) | 0.27% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This affects all users as the shared worker… | |
| Analizada | Media (5.4) | 0.16% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and restricted categories they cannot access, then export their data to… | |
| Analizada | Media (5.9) | 0.30% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private topic/post content made by the users are leaked through the archives… | |
| Analizada | Crítica (9.9) | 0.33% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known… | |
| Analizada | Media (5.3) | 0.24% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated user bypass the ai_discover_persona access controls and gain ongoing DM access to personas that may be wired to staff-only categories, RAG document sets, or automated… | |
| Analizada | Media (5.3) | 0.25% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows attackers to cause noticeable server delays and resource exhaustion… | |
| Analizada | Media (5.3) | 0.19% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available. | |
| Analizada | Media (5.4) | 0.22% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated cross-site scriptinv vulnerability on the Discourse Math plugin when using its KaTeX variant. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and… | |
| Analizada | Media (6.1) | 0.20% | — | Discourse | 28/1/2026 | 17/6/2026 | Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 affects anyone who uses S3 for uploads. While scripts may be executed, they will only be run in the context of the S3/CDN domain, with no site credentials. Versions 3.5.4, 2025.11.2,… | |
| Aplazada | Alta (8.9) | 0.61% | — | Westerndigital WD DiscoveryAI | 26/1/2026 | 17/6/2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path. |