Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
2691 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.55% | — | Fasterxml Jackson-coreAI | 22/9/2026 | 22/9/2026 | NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Stencil CoreAI | 21/9/2026 | 24/9/2026 | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the textContent property of such a component's host element causes the value to be… | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | Stencil CoreAI | 21/9/2026 | 25/9/2026 | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. | |
| Pendiente de análisis | Alta (8.1) | 0.16% | — | Redhat Pki-coreAI | 21/9/2026 | 30/9/2026 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's… | |
| Aplazada | Alta (8.6) | 0.44% | — | Uvdesk Core-frameworkAI | 21/9/2026 | 22/9/2026 | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full… | |
| Aplazada | Media (5.3) | 0.30% | — | Uvdesk Core-frameworkAI | 21/9/2026 | 22/9/2026 | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not… | |
| Aplazada | Media (5.1) | 0.18% | — | Uvdesk Core-frameworkAISwiftmailerAI | 21/9/2026 | 24/9/2026 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members… | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Noobaa-coreAI | 21/9/2026 | 22/9/2026 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz-… | |
| Aplazada | Alta (8.6) | 0.80% | — | Netcore Nbr200v2AI | 21/9/2026 | 21/9/2026 | A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Aplazada | Alta (8.6) | 0.80% | — | Netcore Nbr200v2AI | 20/9/2026 | 21/9/2026 | A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The… | |
| Aplazada | Alta (8.6) | 1.7% | — | Netcore Nbr200v2AI | 20/9/2026 | 22/9/2026 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Alta (8.5) | 2.4% | — | Netcore Nbr200v2AI | 20/9/2026 | 21/9/2026 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is… | |
| Aplazada | Crítica (9.3) | 2.9% | — | Netcore Nbr200v2AI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Alta (8.6) | 2.0% | — | Netcore Nbr200v2AI | 20/9/2026 | 21/9/2026 | A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit… | |
| Aplazada | Alta (8.6) | 2.4% | — | Netcore Nbr200v2AI | 20/9/2026 | 21/9/2026 | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Uutils CoreutilsAI | 18/9/2026 | 22/9/2026 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when… | |
| Analizada | Media (5.7) | 0.15% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys. | |
| Analizada | Media (6.8) | 0.07% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption. | |
| Analizada | Media (6.8) | 0.07% | — | Mongodb Entity Framework Core Provider | 17/9/2026 | 24/9/2026 | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database. | |
| Aplazada | Alta (8.7) | 0.52% | — | Manticore SearchAI | 16/9/2026 | 22/9/2026 | Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that… | |
| Pendiente de análisis | Crítica (9.8) | 0.49% | — | Apache Myfaces CoreAI | 16/9/2026 | 17/9/2026 | Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue. | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Coredns.io CorednsAI | 16/9/2026 | 24/9/2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP,… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Coredns.io CorednsAI | 16/9/2026 | 24/9/2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack on attacker-controlled DNS section counts before… | |
| Aplazada | Alta (7.8) | 0.22% | — | Redocly Respect-coreAIRedocly CLIAI | 16/9/2026 | 24/9/2026 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__… | |
| Aplazada | Media (5.1) | 0.24% | — | Netcore Nr255-vAI | 15/9/2026 | 16/9/2026 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malicious script through these hostname fields, which is later rendered by network_config.js and… |