Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
21.644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.1) | 0.29% | — | Tanium Threat ResponseAI | 19/8/2026 | 1/9/2026 | Tanium addressed a compression bomb vulnerability in Threat Response. | |
| En análisis | Baja (3.1) | 0.29% | — | Tanium FindingsAI | 19/8/2026 | 1/9/2026 | Tanium addressed a compression bomb vulnerability in Findings. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Cisco Unified Intelligence CenterAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Analizada | Media (6.3) | 0.21% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates… | |
| Analizada | Media (4.3) | 0.34% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() renders the record without authorize(),… | |
| Analizada | Alta (7.1) | 0.29% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary /stored-eula-file/{filename} route correctly… | |
| Analizada | Alta (7.6) | 0.30% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose… | |
| Analizada | Media (5.4) | 0.37% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesController.php and… | |
| Analizada | Media (4.9) | 0.35% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips superuser permission but does not strip admin permission. The created… | |
| Analizada | Media (6.3) | 0.33% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be moved across company boundaries and breaking multi-tenant isolation. This… | |
| Analizada | Media (6.3) | 0.27% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes update access but does not enforce canEditAuthFields before clearing… | |
| Analizada | Media (6.5) | 0.49% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/UserImporter.php applies the canEditAuthFields gate by unsetting… | |
| Analizada | Media (5.9) | 0.40% | — | Snipeitapp Snipe-it | 19/8/2026 | 30/9/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php window=1. A successful guess creates a… | |
| Aplazada | Alta (7.2) | 0.47% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into… | |
| Aplazada | Alta (7.4) | 0.46% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |
| Aplazada | Media (6.4) | 0.13% | — | Ingenic T31AIWyze Video Doorbell V2AI | 19/8/2026 | 9/9/2026 | The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker with physical write access to boot media to forge modified SPL (Secondary… | |
| Aplazada | Media (6.8) | 0.15% | — | Ingenic T41AIIngenic T32AIIngenic T40AIIngenic A1AI | 19/8/2026 | 9/9/2026 | The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Nikstore CoreAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Peepso CommunityAI | 19/8/2026 | 20/8/2026 | Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. | |
| Aplazada | Media (4.3) | 0.27% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. | |
| Aplazada | Alta (7.2) | 0.27% | — | Animation Addons FOR ElementorAI | 19/8/2026 | 26/8/2026 | The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back. | |
| Aplazada | Media (5.5) | 0.17% | — | Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI | 18/8/2026 | 9/9/2026 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second… | |
| Aplazada | Media (5.5) | 0.29% | — | Linuxfabrik Monitoring PluginsAI | 18/8/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path… |