Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 332 respecto a la semana anterior
Críticas / altas1275▼ 217 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
21.068 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.80% | — | Append-only-vecAI | 21/8/2026 | 9/9/2026 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. | |
| Analizada | Baja (2.4) | 0.17% | — | Apple Watchos | 21/8/2026 | 24/8/2026 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts. | |
| Analizada | Media (4.3) | 0.36% | — | Apple Macos | 21/8/2026 | 24/8/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Pendiente de análisis | Media (6.7) | 0.20% | 💥 PoC | Canonical ApportAI | 20/8/2026 | 28/8/2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files. | |
| Analizada | Crítica (9.6) | 0.94% | — | Microsoft Azure Logic Apps | 20/8/2026 | 24/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.97% | — | Microsoft Azure WEB Apps | 20/8/2026 | 24/8/2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.43% | — | Apple Container | 20/8/2026 | 1/9/2026 | An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched.… | |
| Analizada | Crítica (9.8) | 0.47% | — | Apple Swiftnio SSH | 20/8/2026 | 3/9/2026 | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1. | |
| Aplazada | Media (6.9) | 0.82% | — | FrappeAI | 20/8/2026 | 10/9/2026 | Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response shapes for registered and unregistered email… | |
| Aplazada | Alta (8.5) | 0.34% | — | FrappeAI | 20/8/2026 | 16/9/2026 | Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in frappe/templates/includes/oauth_confirmation.html, and without… | |
| Analizada | Media (4.3) | 0.34% | — | Apple Container | 20/8/2026 | 27/8/2026 | A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0. | |
| Aplazada | Media (6.9) | 0.26% | — | FrappeAI | 20/8/2026 | 10/9/2026 | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not restricted to POST. An attacker can induce an… | |
| Aplazada | Alta (7.1) | 0.49% | — | FrappeAI | 20/8/2026 | 10/9/2026 | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into individual field names. An authenticated caller… | |
| Aplazada | Media (5.3) | 0.46% | — | FrappeAI | 20/8/2026 | 10/9/2026 | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen state. An authenticated user can… | |
| Analizada | Media (5.3) | 0.37% | — | Apple Swiftnio | 20/8/2026 | 28/8/2026 | An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0. | |
| Aplazada | Media (6.9) | 0.27% | — | Appwrite TemplatesAI | 20/8/2026 | 24/9/2026 | The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await verify(...))", so when the X-Hub-Signature-256… | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Baylan Measuring Instruments Industry AND Trade INC Baylan Smart Meter Management ApplicationAI | 20/8/2026 | 26/8/2026 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142. | |
| Aplazada | Media (5.3) | 0.29% | — | Mycred NEW User ApproveAI | 20/8/2026 | 24/8/2026 | Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Bookingpress Appointment Booking PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Zoom APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are… | |
| Pendiente de análisis | Media (4.3) | 0.12% | — | Venafi APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | MS Graph FOR Active Directory APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Webex APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user… |