Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Crgeary Jamstack DeploymentsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in crgeary JAMstack Deployments wp-jamstack-deployments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JAMstack Deployments: from n/a through <= 1.1.1. | |
| Analizada | Alta (8.8) | 0.37% | — | Tanium Deploy | 5/2/2026 | 17/6/2026 | Tanium addressed an improper input validation vulnerability in Deploy. | |
| Analizada | Media (4.3) | 0.27% | — | Tanium Deploy | 5/2/2026 | 17/6/2026 | Tanium addressed an improper access controls vulnerability in Deploy. | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Siebel Customer Relationship Management Deployment | 20/1/2026 | 17/6/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Analizada | Alta (7) | 0.66% | — | Microsoft OfficeMicrosoft Office Deployment ToolMicrosoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (4.9) | 0.26% | — | Hcltechsw HCL Devops Deploy | 7/1/2026 | 30/9/2026 | In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries. | |
| Analizada | Alta (8.8) | 0.60% | — | Internlm Lmdeploy | 26/12/2025 | 5/10/2026 | LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where torch.load() is called without the weights_only=True parameter when loading model checkpoint files. This allows an attacker to execute arbitrary code on the… | |
| Analizada | Media (4.8) | 0.19% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 17/12/2025 | 17/6/2026 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages. | |
| Analizada | Media (6.1) | 0.19% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 17/12/2025 | 30/9/2026 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages. | |
| Analizada | Media (5.6) | 0.19% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 16/12/2025 | 17/6/2026 | HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions. | |
| Analizada | Media (5.9) | 0.15% | — | Hcltechsw HCL Devops Deploy | 16/12/2025 | 17/6/2026 | HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or… | |
| Analizada | Media (5) | 0.19% | — | IBM Devops DeployIBM Urbancode Deploy | 15/12/2025 | 17/6/2026 | IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP… | |
| Analizada | Media (6.5) | 0.30% | — | IBM Devops Deploy | 15/12/2025 | 17/6/2026 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token. | |
| Modificada | Media (5.9) | 0.19% | — | IBM Devops Deploy | 15/12/2025 | 17/6/2026 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and… | |
| Aplazada | Alta (7.7) | 0.11% | — | Papercut Print DeployAIPapercut NGAIPapercut MFAI | 3/9/2025 | 25/9/2026 | PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the… | |
| Analizada | Media (4.3) | 0.24% | — | IBM Devops Deploy | 2/9/2025 | 30/9/2026 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system. | |
| Analizada | Crítica (9.8) | 0.34% | — | PDQ Smart Deploy | 22/8/2025 | 17/6/2026 | An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll | |
| Analizada | Alta (7.8) | 0.19% | — | PDQ Smart Deploy | 22/8/2025 | 17/6/2026 | Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the \HKLM\SYSTEM\Setup\SmartDeploy component | |
| Analizada | Alta (8.8) | 26% | — | Microsoft WEB Deploy 4.0 | 12/8/2025 | 17/6/2026 | Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (5.3) | 0.39% | — | OAKAIDenoAIDeno DeployAINodejsAI+2 | 9/8/2025 | 17/6/2026 | oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers. | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Analizada | Alta (8.8) | 0.36% | — | Lumigo Autodeploy-layer | 22/5/2025 | 17/6/2026 | Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account. | |
| Analizada | Alta (7.5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry UAA Release | 13/5/2025 | 17/6/2026 | Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. | |
| Modificada | Crítica (9.4) | 0.67% | — | Tibco Spotfire Enterprise Runtime FOR RTibco Spotfire Statistics ServicesTibco Spotfire AnalystTibco Spotfire Deployment KIT+2 | 9/4/2025 | 17/6/2026 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution |