Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
5082 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.24% | — | IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001. | |
| Aplazada | Baja (2.3) | 0.36% | — | Really-simple-plugins Really Simple SecurityAI | 14/9/2026 | 19/9/2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a… | |
| Aplazada | Alta (7.5) | 0.34% | — | Really-simple-plugins Really Simple SecurityAI | 13/9/2026 | 14/9/2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Pendiente de análisis | Crítica (9.5) | 1.4% | — | Configserver Security & FirewallAI | 10/9/2026 | 10/9/2026 | OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally… | |
| Pendiente de análisis | Crítica (9.2) | 2.3% | — | Configserver Security FirewallAI | 10/9/2026 | 10/9/2026 | Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Security Agent MCP ServerAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is… | |
| Pendiente de análisis | Media (4) | 0.45% | — | Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI | 10/9/2026 | 11/9/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware… | |
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Aplazada | Media (6.1) | 0.14% | — | Radcom Horizon Security AnalyzerAI | 8/9/2026 | 8/9/2026 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the… | |
| Pendiente de análisis | Crítica (9.1) | 0.68% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive. | |
| Pendiente de análisis | Crítica (9.1) | 0.46% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. | |
| Pendiente de análisis | Crítica (9.1) | 1.6% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,… | |
| Aplazada | Crítica (9.2) | 0.54% | — | Webpros Configserver Security & FirewallAIWebpros CSF MessengerAI | 4/9/2026 | 9/9/2026 | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects… | |
| Aplazada | Alta (7.5) | 0.46% | — | Malcare SecurityAI | 3/9/2026 | 4/9/2026 | Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | |
| Aplazada | Alta (8.9) | 0.47% | — | Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins Script Security | 2/9/2026 | 22/9/2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Script Security | 2/9/2026 | 22/9/2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration. | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | CA Security DomainAI | 1/9/2026 | 23/9/2026 | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session. | |
| Aplazada | Alta (8.1) | 0.40% | — | Siteground SecurityAI | 31/8/2026 | 1/9/2026 | Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. | |
| Aplazada | Media (6.6) | 0.43% | — | Really-simple-plugins Really Simple SecurityAI | 30/8/2026 | 31/8/2026 | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the… | |
| Analizada | Media (5.3) | 0.29% | — | Vmware Spring Security | 27/8/2026 | 2/9/2026 | Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring Security 7.1.0 | |
| Analizada | Media (5.9) | 0.33% | — | Vmware Spring Security | 27/8/2026 | 2/9/2026 | Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of… | |
| Aplazada | Media (6.5) | 0.21% | — | Summit Security Systems AdisyonproAI | 27/8/2026 | 28/8/2026 | Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0. | |
| Analizada | Alta (8.8) | 0.49% | — | Vmware Spring Security | 27/8/2026 | 1/9/2026 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial… |