Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.36% | — | IBM Datastage ON Cloud PAK FOR Data | 3/3/2026 | 17/6/2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component. | |
| Analizada | Alta (8.8) | 0.36% | — | IBM Datastage ON Cloud PAK FOR Data | 3/3/2026 | 17/6/2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the job subroutine component. | |
| Analizada | Alta (7.5) | 0.24% | — | IBM Datastage ON Cloud PAK FOR Data | 3/3/2026 | 17/6/2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system. | |
| Analizada | Alta (8.6) | 0.41% | — | Google Cloud Build | 3/3/2026 | 17/6/2026 | An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed. | |
| Analizada | Baja (2.9) | 0.19% | — | Fit2cloud Sqlbot | 3/3/2026 | 17/6/2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiated remotely. The… | |
| Analizada | Media (6) | 0.29% | — | Extremenetworks Extremecloud IQ Site Engine | 2/3/2026 | 17/6/2026 | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns the underlying… | |
| Analizada | Baja (2.1) | 0.56% | — | Fit2cloud Sqlbot | 2/3/2026 | 17/6/2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.9) | 0.58% | — | Cloudcharge.se | 27/2/2026 | 17/6/2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the… | |
| Modificada | Alta (8.7) | 0.48% | — | Cloudcharge.se | 27/2/2026 | 17/6/2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access. | |
| Modificada | Crítica (9.3) | 0.53% | — | Cloudcharge.se | 27/2/2026 | 17/6/2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP… | |
| Modificada | Media (6.9) | 0.28% | — | Cloudcharge.se | 27/2/2026 | 17/6/2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | |
| Aplazada | Alta (8.4) | 0.24% | — | Google Cloud Vertex AI WorkbenchAI | 26/2/2026 | 17/6/2026 | A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is… | |
| Analizada | Alta (7.2) | 0.71% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of… | |
| Analizada | Crítica (9) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Analizada | Baja (2.9) | 0.39% | — | Cloudflare Circl | 24/2/2026 | 17/6/2026 | The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3… | |
| Analizada | Crítica (9.1) | 0.60% | — | Cloudhypervisor Cloud Hypervisor | 21/2/2026 | 17/6/2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A malicious guest can overwrite its disk header with a crafted QCOW2 structure… | |
| Aplazada | Alta (7.7) | 0.46% | — | Google Cloud Vertex AIAI | 20/2/2026 | 17/6/2026 | Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably named Cloud… | |
| Aplazada | Alta (8.6) | 0.54% | 💥 PoC | Google Cloud AiplatformAIGoogle Vertex AIAI | 20/2/2026 | 15/7/2026 | Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via… | |
| Aplazada | Media (6.2) | 0.21% | — | Softiron HypercloudAI | 20/2/2026 | 17/6/2026 | HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one year), an authenticated client could use a… | |
| Aplazada | Media (6.5) | 0.17% | — | Wpkube Cool TAG CloudAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cloud cool-tag-cloud allows Stored XSS.This issue affects Cool Tag Cloud: from n/a through <= 2.29. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AIAcronis Cyber Protect 15AI | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build… | |
| Analizada | Media (4.7) | 0.13% | — | Tanium Cloud Workloads | 20/2/2026 | 17/6/2026 | Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension. | |
| Aplazada | Crítica (9.3) | 0.22% | — | Delinea Cloud SuiteAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.This issue affects Cloud Suite: before 25.2 HF1. | |
| Aplazada | Media (5.3) | 0.28% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAI | 18/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1 |