Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
11.341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.57% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 21/5/2026 | 1/9/2026 | Se encontró un fallo en libsolv. Esta vulnerabilidad de desbordamiento de búfer de pila ocurre cuando una víctima procesa un archivo '.solv' especialmente diseñado que contiene valores de tamaño negativos en la función 'repo_add_solv'. Esto lleva a una asignación de memoria de tamaño insuficiente y a una escritura… | |
| Modificada | Media (6.5) | 0.58% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 20/5/2026 | 1/9/2026 | Se encontró una falla en libsolv. Esta vulnerabilidad de desbordamiento de búfer basado en pila ocurre en el analizador de metadatos de Debian de libsolv al procesar metadatos de repositorio de Debian especialmente diseñados. Un atacante podría explotar esto al proporcionar etiquetas de suma de verificación SHA384 o… | |
| Analizada | Alta (7.5) | 0.39% | — | Nvidia Tensorrt | 20/5/2026 | 23/7/2026 | NVIDIA TensorRT contiene una vulnerabilidad donde un atacante podría causar una escritura fuera de límites. Un exploit exitoso de esta vulnerabilidad podría conducir a la manipulación de datos. | |
| Analizada | Crítica (9.8) | 0.59% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad en las pruebas RPC, donde un atacante podría causar una deserialización insegura. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, denegación de servicio, manipulación de datos y revelación de información. | |
| Analizada | Alta (7.5) | 0.47% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad donde un atacante podría causar que un valor de retorno no verificado lleve a una desreferencia de puntero nulo. Un exploit exitoso de esta vulnerabilidad podría conducir a una denegación de servicio. | |
| Analizada | Crítica (9.8) | 0.38% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad de deserialización y un manejador serializado inseguro. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, la manipulación de datos y la revelación de información. | |
| Analizada | Crítica (9.8) | 0.57% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM para cualquier plataforma contiene una vulnerabilidad en el servidor MPI, donde un atacante podría causar una deserialización insegura. Un exploit exitoso de esta vulnerabilidad podría conducir a la ejecución de código, denegación de servicio, manipulación de datos y revelación de información. | |
| Aplazada | Crítica (9.8) | 2.5% | — | Hitarth-gg ZenshinAI | 19/5/2026 | 24/7/2026 | Una vulnerabilidad de inyección de comandos de OS en la ruta Express /stream-to-vlc en hitarth-gg Zenshin anterior a 2.7.0 permite a atacantes remotos ejecutar comandos arbitrarios a través del parámetro url. | |
| Pendiente de análisis | Baja (1.8) | 0.09% | — | QtbaseAIOpensslAI | 19/5/2026 | 29/7/2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory. | |
| Analizada | Alta (7.3) | 0.21% | — | Joplinapp JoplinMsiemens One2html | 18/5/2026 | 24/7/2026 | Joplin es una aplicación de código abierto para tomar notas y gestionar tareas que organiza notas y listas en cuadernos. Las versiones anteriores a la 3.5.7 contienen una vulnerabilidad de salto de ruta en el importador que permite sobrescribir archivos arbitrarios en el disco. El conversor de OneNote no sanea los… | |
| Aplazada | Media (6.3) | 0.27% | — | Opensourcepos Open Source Point OF SaleAI | 18/5/2026 | 17/6/2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity.… | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 8/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Aplazada | Media (5.3) | 0.57% | — | Opensourcepos Open Source Point OF SaleAI | 18/5/2026 | 17/6/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Crypt Openssl Pkcs12 Project Crypt Openssl Pkcs12AI | 17/5/2026 | 17/6/2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Perl Crypt Openssl Pkcs12AI | 17/5/2026 | 17/6/2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a… | |
| Aplazada | Media (5.1) | 0.18% | — | Opensolution Quick.cmsAI | 16/5/2026 | 17/6/2026 | Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Rapid7 Metasploit PROAIOpensslAI | 15/5/2026 | 17/6/2026 | Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | AMD Sensor Fusion HUB DriverAI | 15/5/2026 | 17/6/2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash | |
| Aplazada | Media (5.1) | 0.17% | — | Rust-opensslAI | 14/5/2026 | 17/6/2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a… | |
| Aplazada | Alta (8.7) | 0.21% | — | Rust OpensslAI | 14/5/2026 | 17/6/2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that… | |
| Aplazada | Crítica (9.1) | 0.82% | — | Ritense ValtimoAI | 14/5/2026 | 17/6/2026 | Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions from user-supplied… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | AMD Optional ToolsAIOpensslAI | 14/5/2026 | 17/6/2026 | Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution. | |
| Analizada | Media (6.5) | 0.56% | — | Openstack Ironic | 14/5/2026 | 17/6/2026 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | |
| Analizada | Crítica (9.1) | 0.82% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8. | |
| Analizada | Media (6.5) | 0.38% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or… |