Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
40.054 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.53% | — | Openstack OctaviaAI | 21/9/2026 | 24/9/2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed… | |
| Pendiente de análisis | Crítica (9.4) | 0.53% | — | Openstack OctaviaAI | 21/9/2026 | 22/9/2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw… | |
| Aplazada | Crítica (9.3) | 0.20% | — | Moore Threads MTT S80 Driver PackageAI | 21/9/2026 | 22/9/2026 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about… | |
| Aplazada | Crítica (9.8) | 0.75% | — | UniverAI | 21/9/2026 | 24/9/2026 | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | |
| Aplazada | Crítica (9.8) | 0.75% | — | UniverAI | 21/9/2026 | 22/9/2026 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | |
| Aplazada | Crítica (9.8) | 0.47% | — | NocobaseAI | 21/9/2026 | 22/9/2026 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements. | |
| Aplazada | Crítica (9.1) | 0.45% | — | MaxkbAIAmazon BedrockAIAmazon AWSAI | 21/9/2026 | 22/9/2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS… | |
| Aplazada | Crítica (10) | 1.0% | — | MaxkbAI | 21/9/2026 | 22/9/2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or… | |
| Aplazada | Crítica (9.8) | 0.75% | — | ZlmediakitAI | 21/9/2026 | 24/9/2026 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Joplin ServerAI | 21/9/2026 | 28/9/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker… | |
| Aplazada | Crítica (9.3) | 0.46% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Perl Email-senderAI | 21/9/2026 | 22/9/2026 | Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other… | |
| Aplazada | Crítica (9.9) | 0.62% | — | AjentiAI | 21/9/2026 | 24/9/2026 | Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package… | |
| Pendiente de análisis | Crítica (9.2) | 0.72% | — | Treasuredata Fluent BITAI | 21/9/2026 | 24/9/2026 | Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or… | |
| Aplazada | Crítica (9.8) | 0.56% | — | MailuAIMailu Helm-chartsAI | 21/9/2026 | 24/9/2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header… | |
| Aplazada | Crítica (9.1) | 0.27% | — | Cutephp CutenewsAI | 21/9/2026 | 24/9/2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Apache MinaAI | 21/9/2026 | 22/9/2026 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never… | |
| Analizada | Crítica (9.1) | 0.75% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Eclipse Open VSXAI | 21/9/2026 | 22/9/2026 | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, falling back to the client-supplied Host header. Those responses are… | |
| Aplazada | Crítica (9.8) | 0.55% | — | WEB TO Print Online DesignerAI | 21/9/2026 | 21/9/2026 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server. | |
| Aplazada | Crítica (9.3) | 2.9% | — | Netcore Nbr200v2AI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Crítica (9.3) | 0.98% | — | Dlink Dir-868lAI | 20/9/2026 | 22/9/2026 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a… | |
| Aplazada | Crítica (9.3) | 0.39% | 💥 PoC | Ordasoft Osgallery SearchAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a… |