Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
40.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.69% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code… | |
| Analizada | Crítica (9.8) | 0.85% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | |
| Analizada | Crítica (9.8) | 0.56% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the… | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | IBM Sterling File GatewayAI | 18/9/2026 | 22/9/2026 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. | |
| Pendiente de análisis | Crítica (9.3) | 0.50% | — | CordyscrmAI | 18/9/2026 | 23/9/2026 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFilter.addPublicPathFilters permits the SSE paths, and the endpoints trust the… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Pgxn PG PartmanAI | 18/9/2026 | 23/9/2026 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT… | |
| Aplazada | Crítica (9.8) | 0.59% | — | FluidsynthAI | 18/9/2026 | 24/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Hrp2000 E-hrAI | 18/9/2026 | 22/9/2026 | Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary… | |
| Analizada | Crítica (9.2) | 0.57% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored… | |
| Aplazada | Crítica (9.1) | 0.31% | — | Cocos AIAI | 18/9/2026 | 24/9/2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted,… | |
| Aplazada | Crítica (9.1) | 0.27% | 💥 PoC | Cocos AIAIIntel TDXAI | 18/9/2026 | 24/9/2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote… | |
| Pendiente de análisis | Crítica (9.8) | 0.67% | — | Icinga 2AI | 18/9/2026 | 24/9/2026 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA… | |
| Aplazada | Crítica (9.1) | 0.33% | — | MnemosyneAI | 18/9/2026 | 24/9/2026 | Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. The server accepted any… | |
| Pendiente de análisis | Crítica (9.8) | 0.69% | — | ZeromqAIPyzmqAIInternlm LmdeployAI | 18/9/2026 | 23/9/2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()`… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Carecam Cm2507AI | 18/9/2026 | 21/9/2026 | CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover the associated credential, which may also be reusable across other devices… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Cm2507AI | 18/9/2026 | 19/9/2026 | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key. | |
| Aplazada | Crítica (9.9) | 0.35% | — | WacrmAI | 18/9/2026 | 30/9/2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and… | |
| Aplazada | Crítica (9.8) | 0.61% | 💥 PoC | Struktur LibheifAI | 18/9/2026 | 18/9/2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage.… | |
| Pendiente de análisis | Crítica (9.8) | 0.71% | — | InterchangeAI | 18/9/2026 | 18/9/2026 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits… | |
| Aplazada | Crítica (9.9) | 0.38% | — | KCPAI | 18/9/2026 | 24/9/2026 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can… | |
| Pendiente de análisis | Crítica (9.9) | 0.37% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | |
| Pendiente de análisis | Crítica (10) | 0.57% | — | IBM MQ ApplianceAI | 18/9/2026 | 21/9/2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | |
| Analizada | Crítica (9.8) | 0.45% | — | IBM MQ | 18/9/2026 | 23/9/2026 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled. | |
| Aplazada | Crítica (9.9) | 0.64% | — | Xwiki RenderingAI | 18/9/2026 | 24/9/2026 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and… | |
| Pendiente de análisis | Crítica (10) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 21/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. |