Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.51% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. Attackers with DML access to… | |
| Aplazada | Alta (7.1) | 0.32% | — | MagistralaAIPostgresqlAITimescaledbAI | 5/8/2026 | 26/8/2026 | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and the TimescaleDB reader… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+1 | 27/7/2026 | 11/8/2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… | |
| Aplazada | Media (5.3) | 0.30% | — | Theeventscalendar THE Events CalendarAI | 27/7/2026 | 27/7/2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a… | |
| Analizada | Media (5.5) | 0.16% | — | Dell Powerscale Onefs | 15/7/2026 | 15/7/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Powerscale Onefs | 15/7/2026 | 16/7/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.6) | 0.86% | — | Anyscale RAY | 1/7/2026 | 14/7/2026 | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pickle.loads()… | |
| Analizada | Media (6.5) | 0.27% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow… | |
| Analizada | Crítica (10) | 6.1% | — | IBM Websphere Extreme Scale | 30/6/2026 | 2/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an… | |
| Analizada | Crítica (9.9) | 0.51% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who… | |
| Analizada | Alta (8.8) | 0.55% | — | IBM Websphere Extreme Scale | 30/6/2026 | 3/7/2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including… | |
| Analizada | Alta (8.8) | 0.63% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment | |
| Analizada | Alta (8.8) | 1.0% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 27/8/2026 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server | |
| Analizada | Alta (8.8) | 0.50% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | |
| Analizada | Alta (8.7) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Media (6.9) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Alta (7.1) | 0.58% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | |
| Aplazada | Alta (7.7) | 2.3% | — | Luci-app-tailscale-communityAI | 29/6/2026 | 14/7/2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a… | |
| Aplazada | Baja (1.3) | 0.18% | — | MyscaledbAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulation results in insufficient verification of data authenticity. It is possible to launch the attack remotely. A high… | |
| Aplazada | Alta (8.5) | 0.34% | — | Theeventscalendar THE Events CalendarAI | 17/6/2026 | 6/10/2026 | Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. | |
| Modificada | Alta (7.5) | 0.99% | — | Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+2 | 10/6/2026 | 9/9/2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in… |