Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

18.389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.39%—Microsoft Copilot17/9/202625/9/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
AplazadaCrítica (9)0.70%—AnyqueryAIGoogle ChromeAIBraveAIMicrosoft EdgeAI+117/9/202630/9/2026
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript or…
AplazadaAlta (7.1)0.50%—RosarosisAI17/9/202622/9/2026
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users'…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredicatsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to…
AplazadaBaja (1.2)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be…
AplazadaBaja (2.7)0.43%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
AplazadaBaja (1.2)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation…
AplazadaMedia (4.9)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially…
AplazadaMedia (4.9)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
Pendiente de análisisAlta (8.5)0.19%—Microsoft LightgbmAI16/9/202624/9/2026
LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_…
AplazadaAlta (8.7)0.91%—Zlt2000 Microservices-platformAI16/9/202616/9/2026
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role…
AplazadaAlta (7.2)0.54%—Zlt2000 Microservices-platformAI16/9/202624/9/2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and metadata by supplying…
AplazadaAlta (7.1)0.48%—Zlt2000 Microservices-platformAIElasticsearchAI16/9/202618/9/2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers…
AplazadaAlta (8.7)0.46%—Zlt2000 Microservices-platformAI16/9/202621/9/2026
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password…
Pendiente de análisisAlta (8.2)0.58%—Mikrotik RouterosAI16/9/202624/9/2026
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that…
Pendiente de análisisMedia (6.3)0.39%—Mikrotik RouterosAI16/9/202624/9/2026
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the…
AnalizadaAlta (8.8)0.82%—Microsoft Edge Chromium15/9/202625/9/2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Edge Chromium15/9/202625/9/2026
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Pendiente de análisisAlta (7.6)0.37%—CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI15/9/202617/9/2026
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as…
Pendiente de análisisAlta (8.8)0.08%—Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI15/9/202618/9/2026
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.…
AplazadaAlta (8.7)0.48%—LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI15/9/202630/9/2026
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can…
Pendiente de análisisMedia (6.9)0.38%—Mikrotik RouterosAI14/9/202624/9/2026
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path…
Pendiente de análisisMedia (5.3)0.49%—Mikrotik RouterosAI14/9/202624/9/2026
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write…