Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.31% | — | ABB Ability EdgeniusAI | 20/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1. | |
| Analizada | Media (4.4) | 0.23% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. | |
| Analizada | Media (5.4) | 0.28% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | |
| Aplazada | Alta (8.8) | 0.33% | — | Observability OperatorAI | 12/11/2025 | 21/9/2026 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create… | |
| Analizada | Media (4.6) | 0.24% | — | Solarwinds Observability Self-hosted | 21/10/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account. | |
| Aplazada | Media (6.4) | 0.20% | — | Vulnerability-lookupAI | 25/9/2025 | 30/9/2026 | vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instance who can add bundles, comments, or sightings. A cross-site scripting (XSS) vulnerability was discovered in the handling of user-supplied input in the Bundles, Comments, and Sightings components.… | |
| Aplazada | Alta (8.7) | 0.36% | — | ABB Ability ZenonAI | 13/8/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14. | |
| Aplazada | Media (4.8) | 0.15% | — | Intel Local Manageability ServiceAI | 12/8/2025 | 17/6/2026 | Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Media (5.9) | 0.33% | — | Intel AMTAIIntel Standard ManageabilityAI | 12/8/2025 | 17/6/2026 | Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access. | |
| Analizada | Alta (7.8) | 0.29% | — | Solarwinds Observability Self-hosted | 24/7/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account… | |
| Aplazada | Media (5.9) | 0.73% | — | Trustyai ExplainabilityAI | 20/6/2025 | 17/6/2026 | A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy… | |
| Analizada | Media (4.3) | 0.21% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required. | |
| Analizada | Media (4.8) | 0.19% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. | |
| Aplazada | Media (5.4) | 0.32% | — | Ability INC Accessibility SuiteAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.19. | |
| Analizada | Alta (7.8) | 0.16% | — | AMD Aim-t Manageability API | 13/5/2025 | 17/6/2026 | Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.8) | 0.16% | — | AMD Aim-t Manageability API | 13/5/2025 | 17/6/2026 | A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.3) | 0.22% | — | AMD Cloud Manageability ServiceAI | 13/5/2025 | 17/6/2026 | Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.3) | 0.22% | — | Aim-t Manageability ServiceAI | 13/5/2025 | 17/6/2026 | Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution. | |
| Aplazada | Media (4.3) | 0.15% | — | Ability INC WEB Accessibility With MAX AccessAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Cross Site Request Forgery.This issue affects Web Accessibility with Max Access: from n/a through <= 2.0.9. | |
| Aplazada | Alta (7.1) | 0.14% | — | Offshorewebmaster Availability CalendarAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4. | |
| Aplazada | Alta (8.5) | 0.49% | — | Ability INC Accessibility SuiteAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Accessibility Suite online-accessibility allows SQL Injection.This issue affects Accessibility Suite: from n/a through <= 4.18. | |
| Aplazada | Media (6.5) | 0.22% | — | Ability INC Accessibility SuiteAI | 10/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue affects Accessibility Suite: from n/a through <= 4.18. | |
| Aplazada | Media (6.4) | 0.24% | — | Vulnerability-lookupAI | 8/4/2025 | 17/6/2026 | Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py. | |
| Modificada | Alta (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. |