Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
40.037 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 26/9/2026 | Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as… | |
| Pendiente de análisis | Crítica (9.4) | 0.46% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 0.85% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 25/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read… | |
| Pendiente de análisis | Crítica (9.4) | 1.7% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write… | |
| Pendiente de análisis | Crítica (9.4) | 1.5% | — | Lantronix Slc8000AILantronix Emg8500AILantronix Emg7500AILantronix Slb882AI+2 | 22/9/2026 | 24/9/2026 | Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read… | |
| Pendiente de análisis | Crítica (9.3) | 1.1% | — | VectorAI | 22/9/2026 | 25/9/2026 | Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result without confining it to an intended directory. When an untrusted source supplies an event field used by the path template, the value can contain an… | |
| Pendiente de análisis | Crítica (9.3) | 0.29% | — | AnyioAI | 22/9/2026 | 28/9/2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of IDNA 2008. When a connection to a… | |
| Analizada | Crítica (9.3) | 2.2% | ⚠ Explotación activa💥 PoC | F5 Big-ip Access Policy Manager | 22/9/2026 | 23/9/2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource… | |
| Pendiente de análisis | Crítica (9.8) | 0.73% | — | Lmsys SglangAI | 22/9/2026 | 22/9/2026 | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads()… | |
| Pendiente de análisis | Crítica (9.6) | 0.38% | 💥 PoC | Fortinet Fortipam Chrome ExtensionAI | 22/9/2026 | 26/9/2026 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack | |
| Aplazada | Crítica (9.8) | 0.38% | — | Webpy Web.pyAI | 22/9/2026 | 22/9/2026 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and… | |
| Analizada | Crítica (9.8) | 1.6% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.42% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 0.23% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| Analizada | Crítica (9.8) | 0.45% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.67% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Pendiente de análisis | Crítica (9.3) | 2.1% | 💥 PoC | Dlink Dap-1360AI | 22/9/2026 | 22/9/2026 | D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Karel Electronic Industry AND Trade KarelipsAI | 22/9/2026 | 22/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Pendiente de análisis | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 23/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | |
| Analizada | Crítica (9.8) | 0.32% | — | Qualcomm Software Center | 22/9/2026 | 25/9/2026 | Improper authorization leads to Remote Code Execution via SocketIO interface. | |
| Aplazada | Crítica (9.3) | 0.30% | — | — | 22/9/2026 | 22/9/2026 | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parameter. An unauthenticated attacker could manipulate the identifier and reset the… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Erlang OTPAIErlang SSLAI | 22/9/2026 | 22/9/2026 | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's… | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa | Arista Velocloud Orchestrator | 22/9/2026 | 23/9/2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.… |