Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

5121 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.1)0.31%—Mediawiki11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
AnalizadaBaja (2.1)0.33%—Mediawiki11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
AnalizadaMedia (5.5)0.40%—Mediawiki11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
AnalizadaMedia (4.8)0.38%—Mediawiki Checkuser11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.
AnalizadaBaja (2.3)0.43%—Wikimedia Scribunto11/5/202611/8/2026
Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.
AnalizadaBaja (1.3)0.40%—Mediawiki11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
AnalizadaMedia (5.1)0.37%—Mediawiki11/5/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
Pendiente de análisisBaja (2.1)0.32%—Wikimedia AbusefilterAI11/5/202617/6/2026
Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2.
AnalizadaMedia (6.7)0.15%—Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+284/5/202617/6/2026
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.
AnalizadaMedia (6.5)0.29%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+474/5/202617/6/2026
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;…
AnalizadaMedia (6.5)0.22%—Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+644/5/202617/6/2026
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue…
AnalizadaMedia (6.7)0.15%—Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+184/5/202617/6/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.
AnalizadaMedia (6.7)0.11%—Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+134/5/202617/6/2026
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.
AplazadaBaja (2.1)0.42%—AV Stumpfl Pixera TWO Media ServerAI3/5/202617/6/2026
A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix…
AplazadaMedia (6.5)0.34%—Najeebmedia Frontend File ManagerAI3/5/202617/6/2026
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user…
AnalizadaMedia (6.3)0.13%—Nvidia Nemoclaw28/4/202617/6/2026
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this…
AnalizadaAlta (8.6)0.40%—Nvidia Nemoclaw28/4/202617/6/2026
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A…
AnalizadaMedia (6.5)0.36%—Nvidia Nvflare28/4/202617/6/2026
NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.
AnalizadaAlta (8.8)0.48%—Nvidia Nvflare28/4/202617/6/2026
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
AnalizadaCrítica (9.8)0.57%—Nvidia Nvflare28/4/202617/6/2026
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code…
AplazadaMedia (6.9)0.40%—Klik SocialmediawebsiteAI25/4/202617/6/2026
A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely.
Pendiente de análisisAlta (8.2)0.32%—Nvidia Cuda-qAI21/4/202617/6/2026
NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Pendiente de análisisAlta (7.7)0.24%—Nvidia KAI SchedulerAI21/4/202617/6/2026
NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.
Pendiente de análisisMedia (4.3)0.19%—Nvidia KAI SchedulerAI21/4/202617/6/2026
NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.
AplazadaMedia (5.1)0.29%—Semantic-mediawiki Semantic MediawikiAI21/4/202617/6/2026
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal…