Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.55% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 11/9/2026 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The… | |
| Aplazada | Media (5.5) | 0.66% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 8/9/2026 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack… | |
| Aplazada | Media (5.5) | 0.63% | — | Ramon-victor Freegpt-webuiAI | 4/9/2026 | 8/9/2026 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from… | |
| Aplazada | Alta (7.5) | 0.76% | — | Free5gcAI | 4/9/2026 | 14/9/2026 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 14/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 9/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Alta (7.5) | 0.35% | — | FreeipmiAI | 4/9/2026 | 9/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions). | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. | |
| Analizada | Media (5.3) | 0.28% | — | Freerdp | 3/9/2026 | 9/9/2026 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane. | |
| Analizada | Alta (7.1) | 0.38% | — | Freerdp | 3/9/2026 | 9/9/2026 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved… | |
| Aplazada | Baja (3.7) | 0.45% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and XRES* with strings.EqualFold and logs… | |
| Aplazada | Alta (7.5) | 0.42% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by… | |
| Aplazada | Crítica (9.3) | 0.59% | — | Free5gcAI | 28/8/2026 | 8/9/2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBeatTimer ranges, mandatory profile fields, or nfServices.ipEndPoints… | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 1/9/2026 | An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query. | |
| Aplazada | Alta (7.5) | 0.46% | — | Free5gcAI | 27/8/2026 | 31/8/2026 | An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU. |