Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 332 respecto a la semana anterior
Críticas / altas1275▼ 217 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

21.068 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.80%—Append-only-vecAI21/8/20269/9/2026
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
AnalizadaBaja (2.4)0.17%—Apple Watchos21/8/202624/8/2026
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
AnalizadaMedia (4.3)0.36%—Apple Macos21/8/202624/8/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
Pendiente de análisisMedia (6.7)0.20%💥 PoCCanonical ApportAI20/8/202628/8/2026
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
AnalizadaCrítica (9.6)0.94%—Microsoft Azure Logic Apps20/8/202624/8/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.97%—Microsoft Azure WEB Apps20/8/202624/8/2026
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.43%—Apple Container20/8/20261/9/2026
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched.…
AnalizadaCrítica (9.8)0.47%—Apple Swiftnio SSH20/8/20263/9/2026
A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.
AplazadaMedia (6.9)0.82%—FrappeAI20/8/202610/9/2026
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email…
AplazadaAlta (8.5)0.34%—FrappeAI20/8/202616/9/2026
Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in frappe/templates/includes/oauth_confirmation.html, and without…
AnalizadaMedia (4.3)0.34%—Apple Container20/8/202627/8/2026
A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.
AplazadaMedia (6.9)0.26%—FrappeAI20/8/202610/9/2026
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not restricted to POST. An attacker can induce an…
AplazadaAlta (7.1)0.49%—FrappeAI20/8/202610/9/2026
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into individual field names. An authenticated caller…
AplazadaMedia (5.3)0.46%—FrappeAI20/8/202610/9/2026
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen state. An authenticated user can…
AnalizadaMedia (5.3)0.37%—Apple Swiftnio20/8/202628/8/2026
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
AplazadaMedia (6.9)0.27%—Appwrite TemplatesAI20/8/202624/9/2026
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await verify(...))", so when the X-Hub-Signature-256…
AplazadaCrítica (9.8)0.64%💥 PoCBaylan Measuring Instruments Industry AND Trade INC Baylan Smart Meter Management ApplicationAI20/8/202626/8/2026
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
AplazadaMedia (5.3)0.29%—Mycred NEW User ApproveAI20/8/202624/8/2026
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8.
AplazadaCrítica (9.3)0.40%—Bookingpress Appointment Booking PROAI20/8/202620/8/2026
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Pendiente de análisisMedia (4.3)0.19%—Zoom APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are…
Pendiente de análisisMedia (4.3)0.12%—Venafi APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user…
Pendiente de análisisMedia (4.3)0.19%—MS Graph FOR Active Directory APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.…
Pendiente de análisisMedia (4.3)0.19%—Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in…
Pendiente de análisisMedia (4.3)0.19%—Cisco Webex APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The…
Pendiente de análisisMedia (4.3)0.19%—Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user…