Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

535 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.18%—Unity ParsecAI4/7/20266/7/2026
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running…
AplazadaAlta (7.7)2.3%—Luci-app-tailscale-communityAI29/6/202614/7/2026
luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a…
Pendiente de análisisAlta (8)1.3%—Dell Csi-powerstoreAIDell Csi-unityAIDell Csi-powerflexAIDell Csi-powermaxAI26/6/202626/6/2026
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially…
AnalizadaMedia (6.5)0.41%—Oracle Peoplesoft Enterprise Campus Software Campus Community17/6/202631/7/2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS…
AnalizadaAlta (8.1)0.44%—Oracle Peoplesoft Enterprise Campus Software Campus Community17/6/202631/7/2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.…
AplazadaMedia (5.9)0.43%—Fastnetmon Community EditionAI2/6/202622/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without…
AnalizadaMedia (6.5)0.28%—Springaicommunity MCP Security29/5/202621/7/2026
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for…
AplazadaMedia (6.5)0.44%—Fastnetmon Community EditionAI26/5/202624/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end…
AnalizadaAlta (8.7)0.50%—Hacs Home Assistant Community Store16/5/202617/6/2026
Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft…
AnalizadaAlta (7.2)0.30%—Cisco Unity Connection6/5/20268/7/2026
A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP…
AnalizadaAlta (8.8)0.71%—Cisco Unity Connection6/5/20261/7/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a…
AplazadaMedia (6.1)0.25%—Diskover-communityAI27/4/20265/7/2026
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter
AplazadaMedia (6.1)0.25%—Diskover-communityAI27/4/20265/7/2026
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter
AplazadaAlta (8.8)0.24%—Diskoverdata Diskover-communityAI27/4/20265/7/2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
AplazadaCrítica (9.4)0.41%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.
AnalizadaMedia (6.5)0.39%—Cisco Unity Connection15/4/202617/6/2026
These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
AnalizadaMedia (6.5)0.39%—Cisco Unity Connection15/4/202617/6/2026
These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
AnalizadaMedia (6.5)0.23%—Cisco Unity Connection15/4/202617/6/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to…
AnalizadaMedia (4.7)0.20%—Cisco Unity Connection15/4/202617/6/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a…
AnalizadaMedia (6.1)0.19%—Cisco Unity Connection15/4/202617/6/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An…
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.