Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
40.035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.34% | — | OpencodeAI | 22/9/2026 | 24/9/2026 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload. | |
| Aplazada | Crítica (9.8) | 0.32% | — | McmsAI | 22/9/2026 | 6/10/2026 | MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. | |
| Pendiente de análisis | Crítica (9.3) | 0.53% | — | LwipAIMqttAI | 22/9/2026 | 23/9/2026 | lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system… | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 25/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known… | |
| Aplazada | Crítica (9.2) | 0.51% | — | Ltsecurity Ltk3500sfAI | 22/9/2026 | 24/9/2026 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to… | |
| Pendiente de análisis | Crítica (9.8) | 0.65% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Pendiente de análisis | Crítica (9.3) | 0.39% | — | Home-assistant Home AssistantAI | 22/9/2026 | 23/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without… | |
| Pendiente de análisis | Crítica (9.8) | 0.41% | — | McmsAI | 22/9/2026 | 25/9/2026 | MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do). | |
| Pendiente de análisis | Crítica (9.6) | 0.73% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope… | |
| Pendiente de análisis | Crítica (9.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Analizada | Crítica (9.1) | 0.62% | — | Mcp-atlassian MCP Atlassian | 22/9/2026 | 28/9/2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform… | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 25/9/2026 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Crítica (9.3) | 0.32% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.64% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a… | |
| Analizada | Crítica (9.3) | 0.30% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 26/9/2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.9) | 0.55% | — | Adobe ConnectAdobe Connect FOR Mobile | 22/9/2026 | 25/9/2026 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially… | |
| Pendiente de análisis | Crítica (9.9) | 0.64% | — | Plone App.portletsAI | 22/9/2026 | 23/9/2026 | plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro… | |
| Analizada | Crítica (9.9) | 0.53% | — | Adobe Campaign | 22/9/2026 | 26/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 0.34% | — | Adobe Campaign | 22/9/2026 | 25/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9.9) | 0.35% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is… |