Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
21.644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.27% | — | Mira Android Companion APPAI | 11/8/2026 | 1/9/2026 | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject… | |
| Pendiente de análisis | Alta (8.7) | 0.40% | — | Mira Hormone MonitorAI | 11/8/2026 | 3/9/2026 | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Mira Hormone MonitorAI | 11/8/2026 | 3/9/2026 | The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Analizada | Media (5.3) | 0.34% | — | Snipeitapp Snipe-it | 11/8/2026 | 21/8/2026 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated,… | |
| Aplazada | Alta (7.1) | 0.30% | — | Openim ServerAI | 11/8/2026 | 24/9/2026 | OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/get_all_users_uid, and /group/get_groups. Attackers can exploit the absent… | |
| Analizada | Alta (7.2) | 1.0% | — | Microsoft Azure Monitor Agent | 11/8/2026 | 13/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Media (6.9) | 0.13% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (6.9) | 0.10% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 31/8/2026 | Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access… | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | Google TurbiniaAI | 11/8/2026 | 26/8/2026 | Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10. | |
| Analizada | Media (6.3) | 0.33% | — | Intel Transfer Learning Tool | 11/8/2026 | 18/9/2026 | Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (5.4) | 0.16% | — | Intel Hardware-aware-automated-machine-learning | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Performance Counter Monitor | 11/8/2026 | 2/10/2026 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This… | |
| Analizada | Media (5.8) | 0.07% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 28/9/2026 | Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Analizada | Media (6.9) | 0.13% | — | Intel Neural Processing Unit Driver | 11/8/2026 | 28/9/2026 | Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (6.1) | 0.34% | — | SWC Html MinifierAIGO HtmlAI | 11/8/2026 | 18/9/2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Jboss MarshallingAIInfinispanAI | 11/8/2026 | 9/10/2026 | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. | |
| Pendiente de análisis | Baja (3.8) | 0.29% | — | SAP Advanced Planning AND OptimizationAI | 11/8/2026 | 26/8/2026 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Aplazada | Media (4.4) | 0.12% | — | Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI | 10/8/2026 | 1/9/2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before… | |
| Pendiente de análisis | Baja (2.1) | 0.60% | — | Phoenixframework Phoenix Live ViewAI | 10/8/2026 | 12/8/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to value containing ASCII tab, LF or CR. redirect/2 validates :to through the private validate_local_url!/2 in… | |
| Aplazada | Alta (8.8) | 0.40% | — | Nishishi Factory TegalogAI | 10/8/2026 | 28/8/2026 | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management… | |
| Aplazada | Baja (1.9) | 0.17% | — | Nikolaibibo Claude-comfyui-mcpAI | 9/8/2026 | 13/8/2026 | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached locally. The project was informed of the… |