Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

8451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.21%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)3.9%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)0.21%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AplazadaAlta (8.4)0.17%—Sony Optical Disc Archive SoftwareAI5/11/202517/6/2026
Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
AplazadaMedia (4.3)0.27%—WP DiscourseAI1/11/202517/6/2026
The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin unconditionally sending Discourse API credentials (Api-Key and Api-Username headers) to any host specified in a post's discourse_permalink custom field during comment…
AplazadaAlta (7.5)0.42%—ISC KEAAI29/10/20258/10/2026
Para desencadenar el problema, tres parámetros de configuración deben tener ajustes específicos: 'hostname-char-set' debe dejarse en la configuración predeterminada, que es '[^A-Za-z0-9.-]'; 'hostname-char-replacement' debe estar vacío (el valor predeterminado); y 'ddns-qualifying-suffix' NO debe estar vacío (el valor…
AnalizadaMedia (6.3)0.30%—Discourse28/10/202517/6/2026
Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This…
AplazadaMedia (6.3)0.26%—Discussion BoardAI25/10/20258/10/2026
El plugin The Discussion Board - WordPress Forum Plugin para WordPress es vulnerable a la ejecución arbitraria de shortcodes en todas las versiones hasta la 2.5.5, inclusive. Esto se debe a que el software permite a los usuarios ejecutar una acción que no valida correctamente un valor antes de ejecutar do_shortcode.…
AplazadaAlta (7.5)11%—ISC BindAI22/10/20258/10/2026
Consultar registros dentro de una zona especialmente diseñada que contiene ciertos registros DNSKEY malformados puede llevar al agotamiento de la CPU. Este problema afecta a las versiones de BIND 9 9.18.0 hasta 9.18.39, 9.20.0 hasta 9.20.13, 9.21.0 hasta 9.21.12, 9.18.11-S1 hasta 9.18.39-S1, y 9.20.9-S1 hasta…
AplazadaAlta (8.6)0.47%—ISC BindAI22/10/20258/10/2026
En circunstancias específicas, debido a una debilidad en el Generador de Números Pseudoaleatorios (PRNG) que se utiliza, es posible para un atacante predecir el puerto de origen y el ID de consulta que BIND utilizará. Este problema afecta a las versiones de BIND 9 9.16.0 a 9.16.50, 9.18.0 a 9.18.39, 9.20.0 a 9.20.13,…
AplazadaAlta (8.6)0.67%💥 PoCISC BindAI22/10/20258/10/2026
Bajo ciertas circunstancias, BIND es demasiado indulgente al aceptar registros de respuestas, permitiendo a un atacante inyectar datos falsificados en la caché. Este problema afecta a las versiones de BIND 9 9.11.0 hasta 9.16.50, 9.18.0 hasta 9.18.39, 9.20.0 hasta 9.20.13, 9.21.0 hasta 9.21.12, 9.11.3-S1 hasta…
AplazadaMedia (5.8)0.38%—Cisco Snort 3AI15/10/202517/6/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could…
AnalizadaCrítica (9.1)0.48%—Cisco Snort15/10/202517/9/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. This vulnerability is due to an error in the logic of buffer handling when the MIME…
AnalizadaMedia (6.1)0.29%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/20258/10/2026
Una vulnerabilidad en la UI web de Cisco Desk Phone serie 9800, Cisco IP Phone series 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado realizar ataques XSS contra un usuario de la UI web. Esta vulnerabilidad existe porque la UI web de un…
AnalizadaAlta (7.5)0.48%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/20258/10/2026
Una vulnerabilidad en la interfaz de usuario web de las series Cisco Desk Phone 9800, Cisco IP Phone 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado causar una condición de DoS en un dispositivo afectado. Esta vulnerabilidad se debe a un…
AnalizadaMedia (4.9)0.36%—Cisco Telepresence Collaboration EndpointCisco Roomos15/10/20258/10/2026
Una vulnerabilidad en el componente de registro de Cisco TelePresence Collaboration Endpoint (CE) y el software Cisco RoomOS podría permitir a un atacante remoto y autenticado ver información sensible en texto claro en un sistema afectado. Para explotar esta vulnerabilidad, el atacante debe tener credenciales…
AplazadaCrítica (9.3)0.46%—Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI2/10/202517/6/2026
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This…
AnalizadaMedia (5.5)0.30%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites. This issue is fixed in version 3.5.1.
ModificadaMedia (4.3)0.25%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to access. By modifying the “topic_id” value in API…
AnalizadaMedia (5.4)0.20%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AplazadaMedia (4.3)0.28%—Webmaniabr Nota Fiscal Eletronica WoocommerceAI26/9/202517/6/2026
Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.
AplazadaMedia (5.9)0.24%—Webmaniabr Nota Fiscal Eletronica WoocommerceAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Stored XSS.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9.