Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5317 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.7) | 0.21% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and… | |
| En análisis | Alta (7.5) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| En análisis | Media (4.3) | 0.20% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts… | |
| En análisis | Alta (7.2) | 0.50% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | |
| Pendiente de análisis | Alta (8.5) | 0.12% | — | Catonetworks SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 30/9/2026 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09 | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 29/9/2026 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09 | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Windriver VxworksAI | 28/9/2026 | 29/9/2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Windriver VxworksAI | 28/9/2026 | 28/9/2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. | |
| Aplazada | Media (5.9) | 0.19% | — | Nextscripts Social Networks Auto PosterAI | 27/9/2026 | 28/9/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Thoughtworks GocdAI | 23/9/2026 | 30/9/2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A… | |
| Aplazada | Media (5.3) | 0.43% | — | Thoughtworks GocdAI | 23/9/2026 | 30/9/2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and… | |
| Analizada | Media (5.3) | 0.42% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure… | |
| Analizada | Media (5.3) | 0.51% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could… | |
| Analizada | Alta (7.1) | 0.26% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. | |
| Analizada | Alta (7.2) | 0.84% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. | |
| Analizada | Alta (7.3) | 0.41% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful… | |
| Analizada | Alta (7.5) | 0.46% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could… | |
| Analizada | Alta (7.5) | 0.54% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could… | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 28/9/2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system… | |
| Analizada | Crítica (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 22/9/2026 | 25/9/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known… | |
| Pendiente de análisis | Alta (7) | 0.48% | — | Thoughtworks GocdAI | 21/9/2026 | 25/9/2026 | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user… | |
| Pendiente de análisis | Baja (2.3) | 0.58% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends dedicated username and password fields or… | |
| Pendiente de análisis | Media (4.9) | 0.59% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeline group… |