Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3692 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.42% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. | |
| Analizada | Media (6.9) | 0.27% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges… | |
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | Brightsign Digital Signage Diagnostic WEB ServerAI | 10/12/2025 | 17/6/2026 | BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to… | |
| Analizada | Alta (8.8) | 0.90% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations… | |
| Analizada | Media (5) | 0.21% | — | Jenkins GIT Client | 10/12/2025 | 17/6/2026 | Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Github Copilot | 9/12/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. | |
| Aplazada | Alta (7.1) | 0.45% | — | Digitalpa Legality WhistleblowingAI | 9/12/2025 | 17/6/2026 | Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and… | |
| Modificada | Media (6.4) | 0.25% | — | Gitlab | 5/12/2025 | 26/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions. | |
| Analizada | Alta (8.7) | 0.43% | — | Digitalbazaar Forge | 26/11/2025 | 17/6/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a… | |
| Analizada | Media (6.3) | 0.32% | — | Digitalbazaar Forge | 26/11/2025 | 17/6/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller,… | |
| Modificada | Media (6.5) | 0.41% | — | Gitlab | 26/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing. | |
| Modificada | Media (4.3) | 0.32% | — | Gitlab | 26/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions. | |
| Modificada | Media (5.3) | 0.25% | — | Gitlab | 26/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions. | |
| Modificada | Media (6.5) | 0.29% | — | Gitlab | 26/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests. | |
| Modificada | Alta (7.5) | 0.51% | — | Gitlab | 26/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads. | |
| Analizada | Alta (8.6) | 0.74% | — | Digitalbazaar Forge | 25/11/2025 | 17/6/2026 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions. | |
| Aplazada | Crítica (9.3) | 4.1% | — | Shenzhen TVT Digital Technology Nvms-9000AI | 24/11/2025 | 17/6/2026 | Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and… | |
| Aplazada | Alta (8.7) | 0.86% | — | Shenzhen TVT Digital Technology Nvms-9000AI | 24/11/2025 | 26/9/2026 | Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP payload to an exposed NVMS-9000 control port, an unauthenticated remote attacker can… | |
| Aplazada | Media (4.3) | 0.19% | — | Merlot Digital TNC Toolbox WEB PerformanceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4. | |
| Analizada | Media (6.5) | 0.36% | — | Gitlab | 21/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API. | |
| Aplazada | Baja (2.1) | 0.29% | — | Bestfeng OA GIT FreeAI | 15/11/2025 | 17/6/2026 | A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is… | |
| Analizada | Media (6.5) | 0.42% | — | Gitlab | 15/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting patterns. | |
| Analizada | Media (4.3) | 0.33% | — | Gitlab | 15/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through… | |
| Analizada | Media (4.3) | 0.36% | — | Gitlab | 15/11/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests. | |
| Analizada | Baja (3.5) | 0.27% | — | Gitlab | 15/11/2025 | 17/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments. |