Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

1025 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1)0.20%—Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI29/5/202621/7/2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an…
AnalizadaAlta (7.7)0.35%—Oracle Financials Common Modules28/5/202621/7/2026
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.…
ModificadaAlta (8.5)0.30%—Oracle Financials Common Modules28/5/202621/7/2026
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.…
AplazadaCrítica (9.8)0.52%—WosdefaulthttpmoduleAI27/5/202617/6/2026
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
AplazadaAlta (7.5)0.50%—WosdefaulthttpmoduleAI27/5/202617/6/2026
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
AplazadaAlta (7.5)0.46%—WOS Http Status ModuleAI27/5/202617/6/2026
When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is not present in the…
AplazadaAlta (8.5)0.36%—GitoxideAIGIXAIGIX SubmoduleAI26/5/202624/7/2026
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject…
En análisisMedia (5.9)0.33%—Honeywell Control Network ModuleAI21/5/202630/7/2026
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this…
En análisisCrítica (9.1)1.6%—Honeywell Control Network ModuleAI21/5/202630/7/2026
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Honeywell recommends updating to the most recent version of this product, service or offering…
AnalizadaMedia (6.1)0.27%—Simplesamlphp-module-casserver18/5/202630/9/2026
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or…
AnalizadaCrítica (10)1.0%—Dhtmlx PDF Export Module15/5/202617/6/2026
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to…
AnalizadaCrítica (9.2)0.55%—Dhtmlx PDF Export Module15/5/202617/6/2026
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version…
AnalizadaMedia (4.3)0.28%—Linuxfoundation Backstage/plugin-catalog-backend-module-unprocessedLinuxfoundation Backstage/plugin-catalog-unprocessed-entitiesLinuxfoundation Backstage/plugin-catalog-unprocessed-entities-common14/5/202617/6/2026
Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is…
AplazadaCrítica (9.3)0.21%—Misp ModulesAI13/5/202617/6/2026
MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home…
AplazadaMedia (5.8)0.13%—Misp ModulesAI13/5/202617/6/2026
MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side…
AplazadaAlta (7.1)0.15%—Backdropcms Salesforce ModuleAI12/5/202617/6/2026
The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Pendiente de análisisMedia (5.3)0.08%—Ezviz APPAIEzviz Cloud Feature ModulesAI9/5/202625/7/2026
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature.
AnalizadaAlta (7.8)3.4%⚠ Explotación activaLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaAlta (7.8)0.22%—Node-modules Compressing21/4/202617/6/2026
Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for…
AplazadaMedia (5.3)0.40%—Silverstripe Assets ModuleAISilverstripe FrameworkAI16/4/202617/6/2026
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file…
AnalizadaCrítica (9.8)2.2%—Ridvay Auto-approval Module31/3/202625/7/2026
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account…
AnalizadaCrítica (9.8)2.2%—Ridvay Auto-approval Module31/3/202625/7/2026
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account…
Pendiente de análisisMedia (6.7)0.16%—Netskope Endpoint DLP ModuleAINetskope ClientAI17/3/202617/6/2026
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would…
Pendiente de análisisMedia (6.8)0.11%—Netskope Endpoint DLP ModuleAINetskope ClientAI17/3/202617/6/2026
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filter communication port, leading to a Blue-Screen-of-Death (BSOD). Successful…
Pendiente de análisisMedia (5.6)0.08%—Intel Uefi Pdasmm ModuleAI10/3/202617/6/2026
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack…