Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.39% | — | Tanium Discover | 26/1/2026 | 17/6/2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Discover. | |
| Analizada | Media (4.9) | 0.44% | — | Tanium Discover | 26/1/2026 | 17/6/2026 | Tanium addressed an improper input validation vulnerability in Discover. | |
| Aplazada | Alta (7.3) | 0.39% | 💥 PoC | Discord ClientAI | 23/1/2026 | 17/6/2026 | Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Alta (7.1) | 0.26% | — | Expresstechsoftware Memberpress Discord AddonAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.4. | |
| Aplazada | Media (4.3) | 0.29% | 💥 PoC | DiscordAI | 22/1/2026 | 13/9/2026 | Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is… | |
| Aplazada | Media (4.8) | 0.20% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 21/1/2026 | 17/6/2026 | These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the… | |
| Aplazada | Media (6) | 0.12% | — | Cisco Intersight Virtual ApplianceAI | 21/1/2026 | 17/6/2026 | A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerability is due to improper file permissions on configuration files for system accounts… | |
| Aplazada | Media (5.3) | 0.37% | — | Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI | 21/1/2026 | 17/6/2026 | A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by… | |
| Aplazada | Media (4.8) | 0.20% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 21/1/2026 | 17/6/2026 | These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the… | |
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Aplazada | Alta (7.5) | 9.2% | — | ISC BindAI | 21/1/2026 | 1/9/2026 | Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1. | |
| Aplazada | Alta (8.5) | 0.17% | — | Acer Backup ManagerAINTI IschedulesvcAI | 16/1/2026 | 17/6/2026 | Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with… | |
| Analizada | Media (4.8) | 0.39% | — | Stackideas Easydiscuss | 16/1/2026 | 17/6/2026 | User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening. | |
| Analizada | Crítica (9.4) | 0.20% | — | Stackideas Easydiscuss | 16/1/2026 | 17/6/2026 | Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla. | |
| Analizada | Crítica (9.4) | 0.20% | — | Stackideas Easydiscuss | 16/1/2026 | 17/6/2026 | Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla. | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Analizada | Media (4.8) | 0.26% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient… | |
| Aplazada | Media (4.9) | 6.2% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 7/1/2026 | 17/6/2026 | This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the… | |
| Aplazada | Media (5.3) | 0.60% | — | Cisco Snort 3AI | 7/1/2026 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error… | |
| Aplazada | Media (5.8) | 0.67% | — | Cisco Snort 3AI | 7/1/2026 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an… | |
| Aplazada | Media (4.3) | 0.18% | — | Wpdiscover Accordion Slider GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7. | |
| Aplazada | Media (5.4) | 0.12% | — | Iscripts EasyindexAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n/a through <= 1.1.1704. | |
| Analizada | Media (6.3) | 0.29% | — | Discourse | 30/12/2025 | 17/6/2026 | Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix. | |
| Aplazada | Media (4.3) | 0.18% | — | Marketing Fire Wp-discussion-boardAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Discussion Board: from n/a through <= 2.5.7. |