Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

5082 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.1)0.24%—IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI14/9/202616/9/2026
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
AplazadaBaja (2.3)0.36%—Really-simple-plugins Really Simple SecurityAI14/9/202619/9/2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a…
AplazadaAlta (7.5)0.34%—Really-simple-plugins Really Simple SecurityAI13/9/202614/9/2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
Pendiente de análisisCrítica (9.5)1.4%—Configserver Security & FirewallAI10/9/202610/9/2026
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally…
Pendiente de análisisCrítica (9.2)2.3%—Configserver Security FirewallAI10/9/202610/9/2026
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the…
Pendiente de análisisMedia (5.1)0.44%—Amazon Security Agent MCP ServerAI10/9/202610/9/2026
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is…
Pendiente de análisisMedia (4)0.45%—Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI10/9/202611/9/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware…
Pendiente de análisisCrítica (9.8)3.7%—Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI9/9/202610/9/2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
AplazadaMedia (6.1)0.14%—Radcom Horizon Security AnalyzerAI8/9/20268/9/2026
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the…
Pendiente de análisisCrítica (9.1)0.68%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
Pendiente de análisisCrítica (9.1)0.46%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
Pendiente de análisisCrítica (9.1)1.6%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,…
AplazadaCrítica (9.2)0.54%—Webpros Configserver Security & FirewallAIWebpros CSF MessengerAI4/9/20269/9/2026
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects…
AplazadaAlta (7.5)0.46%—Malcare SecurityAI3/9/20264/9/2026
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
AplazadaAlta (8.9)0.47%—Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI3/9/20263/9/2026
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on…
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AnalizadaMedia (4.3)0.28%—Jenkins Script Security2/9/202622/9/2026
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
AnalizadaMedia (4.3)0.31%—Jenkins Script Security2/9/202622/9/2026
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.
Pendiente de análisisMedia (5.3)0.21%—CA Security DomainAI1/9/202623/9/2026
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
AplazadaAlta (8.1)0.40%—Siteground SecurityAI31/8/20261/9/2026
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
AplazadaMedia (6.6)0.43%—Really-simple-plugins Really Simple SecurityAI30/8/202631/8/2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the…
AnalizadaMedia (5.3)0.29%—Vmware Spring Security27/8/20262/9/2026
Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring Security 7.1.0
AnalizadaMedia (5.9)0.33%—Vmware Spring Security27/8/20262/9/2026
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of…
AplazadaMedia (6.5)0.21%—Summit Security Systems AdisyonproAI27/8/202628/8/2026
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0.
AnalizadaAlta (8.8)0.49%—Vmware Spring Security27/8/20261/9/2026
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial…