Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
5121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.58% | — | Nvidia Triton Inference Server | 20/5/2026 | 24/7/2026 | NVIDIA Triton Inference Server contiene una vulnerabilidad donde un atacante podría causar una omisión de autenticación. Un exploit exitoso de esta vulnerabilidad podría conducir a una escalada de privilegios, denegación de servicio o revelación de información. | |
| Analizada | Crítica (9.8) | 0.59% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad en las pruebas RPC, donde un atacante podría causar una deserialización insegura. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, denegación de servicio, manipulación de datos y revelación de información. | |
| Analizada | Alta (7.5) | 0.47% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad donde un atacante podría causar que un valor de retorno no verificado lleve a una desreferencia de puntero nulo. Un exploit exitoso de esta vulnerabilidad podría conducir a una denegación de servicio. | |
| Analizada | Crítica (9.8) | 0.38% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad de deserialización y un manejador serializado inseguro. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, la manipulación de datos y la revelación de información. | |
| Analizada | Crítica (9.8) | 0.57% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad en el servidor MPI, donde un atacante podría causar una deserialización insegura. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, denegación de servicio, manipulación de datos y revelación de información. | |
| Aplazada | Media (6.4) | 0.41% | — | Diagnosis GeneratorAI | 20/5/2026 | 24/7/2026 | El plugin ??????????????? (Diagnosis Generator) para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del parámetro 'js' en versiones hasta la 1.4.16 inclusive. Esto se debe a la falta de comprobaciones de autorización y a una sanitización de entrada insuficiente en la función themeFunc(). La función… | |
| Modificada | Media (5.1) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user,… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected… | |
| Modificada | Media (5.1) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious… | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Aplazada | Alta (8.8) | 0.28% | — | Egavilanmedia PhpcrudAI | 16/5/2026 | 17/6/2026 | EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database information. | |
| Pendiente de análisis | Crítica (9.2) | 0.55% | — | DiagramAI | 15/5/2026 | 17/6/2026 | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1. | |
| Analizada | Media (6.9) | 0.43% | — | Hedera Guardian | 14/5/2026 | 14/7/2026 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can access the endpoint without providing authentication credentials to obtain usernames, Hedera DIDs,… | |
| Aplazada | Alta (8.8) | 0.24% | — | Appyap Technology AND Information INC Yaay Social Media APPAI | 14/5/2026 | 7/10/2026 | Omisión de autorización a través de una vulnerabilidad de clave controlada por el usuario en la aplicación Yaay Social Media de APPYAP Technology and Information Inc. permite acceder a funcionalidades no restringidas adecuadamente por las ACL. Este problema afecta a la aplicación Yaay Social Media: desde la versión… | |
| Aplazada | Media (6.5) | 0.89% | — | Media SyncAI | 14/5/2026 | 17/6/2026 | The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' parameters. This is due to insufficient validation of user-supplied file paths, which are not checked for directory traversal sequences or restricted to the intended… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI | 13/5/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Relay ServerAIObsidianAI | 12/5/2026 | 17/6/2026 | Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated as having full server permissions. An… | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Media Encoder | 12/5/2026 | 28/8/2026 | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Media Encoder | 12/5/2026 | 28/8/2026 | Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.4) | 0.33% | — | Advanced Social Media IconsAI | 12/5/2026 | 17/6/2026 | The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Pendiente de análisis | Baja (2.3) | 0.38% | — | Wikimedia EchoAI | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php. This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Ninguna (0) | 0.28% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Baja (2) | 0.23% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. |