Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
11.341 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 0.14% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming… | |
| Analizada | Media (5.5) | 0.15% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The… | |
| Analizada | Media (5.5) | 0.15% | — | GNU NanoRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Aplazada | Media (5.1) | 0.26% | — | Deepl Chrome Browser ExtensionAI | 22/4/2026 | 17/6/2026 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user. | |
| Analizada | Alta (7.2) | 0.44% | — | Zfnd Zebra-consensusZfnd Zebrad | 21/4/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and… | |
| Analizada | Media (5.5) | 0.15% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/4/2026 | 1/9/2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read… | |
| Pendiente de análisis | Alta (7.7) | 0.37% | — | Openstack KeystoneAI | 14/4/2026 | 5/8/2026 | En OpenStack Keystone anterior a 28.0.1, el backend de identidad LDAP no convierte el atributo enabled del usuario a un booleano cuando la opción de configuración user_enabled_invert es False (el valor predeterminado). El método _ldap_res_to_model en la clase UserApi solo realizaba la conversión de cadena a booleano… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Las versiones 6.5.24, FP11.7 y anteriores de Adobe Experience Manager están afectadas por una vulnerabilidad de cross-site scripting (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso dentro del contexto del navegador de la víctima. La… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Las versiones 6.5.24, FP11.7 y anteriores de Adobe Experience Manager están afectadas por una vulnerabilidad de cross-site scripting (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso dentro del contexto del navegador de la víctima. La… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Las versiones 6.5.24, FP11.7 y anteriores de Adobe Experience Manager están afectadas por una vulnerabilidad de Cross-Site Scripting (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso dentro del contexto del navegador de la víctima. La… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires… | |
| Pendiente de análisis | Media (5.1) | 0.36% | — | Siemens Industrial Edge Management PROAISiemens Industrial Edge Management VirtualAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user… | |
| Pendiente de análisis | Alta (8.7) | 0.42% | — | Siemens Ruggedcom Crossbow Secure Access Manager PrimaryAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device… | |
| Pendiente de análisis | Alta (8.7) | 0.53% | — | Siemens Sinec NMSAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any… | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | Siemens Sinec NMSAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized… | |
| Analizada | Media (6.3) | 0.14% | — | Siemens Simcenter 3DSiemens Simcenter FemapSiemens Simcenter Star-ccm+ ViewerSiemens Software Center+3 | 14/4/2026 | 29/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0… | |
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Daily Expense Tracking SystemAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Modificada | Alta (7.8) | 0.40% | — | KerasRedhat Openshift AI | 13/4/2026 | 15/7/2026 | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpsoul GreenshiftAI | 11/4/2026 | 17/6/2026 | The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.8.9 This is due to insufficient input sanitization and output escaping in the gspb_greenShift_block_script_assets() function. The function uses str_replace() to… | |
| Pendiente de análisis | Alta (7.3) | 0.19% | — | KeepassxcAIOpensslAI | 11/4/2026 | 17/6/2026 | KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Crítica (9.9) | 0.65% | — | Redhat Openshift AI | 10/4/2026 | 15/7/2026 | A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources. | |
| Pendiente de análisis | Media (5.4) | 0.30% | — | Openstack SkylineAI | 10/4/2026 | 17/6/2026 | OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs. | |
| Analizada | Media (5.3) | 0.33% | — | Openstack Keystone | 10/4/2026 | 17/6/2026 | An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3… | |
| Analizada | Alta (8.2) | 0.48% | — | Opnsense | 9/4/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field of the WebGUI login… |