Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.68% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and… | |
| Analizada | Media (6.9) | 0.34% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+109 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic… | |
| Analizada | Alta (7.7) | 0.22% | — | Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+105 | 3/8/2026 | 29/9/2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be… | |
| Pendiente de análisis | Alta (7.6) | 0.43% | — | Vmware ESXAIVmware WorkstationAIVmware FusionAI | 30/7/2026 | 30/7/2026 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the… | |
| Analizada | Alta (8.7) | 0.90% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Aplazada | Baja (1.9) | 1.1% | — | Syncfusion Ej2-javascript-ui-controlsAI | 22/7/2026 | 23/7/2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (6.8) | 0.47% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue… | |
| Analizada | Alta (7.7) | 0.79% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Baja (2.7) | 0.57% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (7.7) | 0.82% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9) | 0.41% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9.3) | 0.55% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9.1) | 1.1% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of… | |
| Analizada | Crítica (9.9) | 1.2% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Analizada | Crítica (9.3) | 0.41% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does… | |
| Analizada | Alta (8.5) | 0.45% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative… | |
| Analizada | Crítica (9.1) | 1.4% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this… | |
| Analizada | Crítica (9.9) | 1.1% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue… | |
| Analizada | Crítica (9.6) | 0.49% | — | Adobe Coldfusion | 14/7/2026 | 28/8/2026 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.2) | 0.27% | — | Adobe Coldfusion | 13/7/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | |
| Analizada | Alta (8.2) | 0.27% | — | Adobe Coldfusion | 13/7/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | |
| Analizada | Crítica (10) | 1.1% | — | Adobe Coldfusion | 6/7/2026 | 28/8/2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. |