Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
40.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.71% | — | VM2AI | 18/9/2026 | 18/9/2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps… | |
| Aplazada | Crítica (10) | 0.73% | — | VM2 NodevmAI | 18/9/2026 | 21/9/2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit… | |
| Aplazada | Crítica (10) | 0.73% | — | VM2AI | 18/9/2026 | 22/9/2026 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`,… | |
| Aplazada | Crítica (9.1) | 0.65% | — | ImagerAI | 18/9/2026 | 18/9/2026 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for… | |
| Aplazada | Crítica (9.2) | 0.29% | — | ABB Freelance Controller DCPAIABB Freelance Controller Ac700AIABB Freelance Controller Ac800AIABB Freelance Controller Ac900AI | 18/9/2026 | 18/9/2026 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex… | |
| Pendiente de análisis | Crítica (9.8) | 0.60% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Analizada | Crítica (9.8) | 0.47% | — | Hcltech Bigfix Service Management | 18/9/2026 | 8/10/2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile… | |
| Aplazada | Crítica (9.1) | 0.82% | — | AF CompanionAI | 18/9/2026 | 18/9/2026 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution. | |
| Aplazada | Crítica (9.3) | 0.91% | — | Hgiga OakloudsAI | 18/9/2026 | 18/9/2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Horizondb | 17/9/2026 | 25/9/2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Fabric | 17/9/2026 | 25/9/2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.33% | — | Microsoft Azure Billing | 17/9/2026 | 7/10/2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.79% | — | Microsoft Azure Cosmos DB | 17/9/2026 | 29/9/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.67% | — | Microsoft Azure AI Foundry | 17/9/2026 | 25/9/2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.1) | 0.44% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.60% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure ARC | 17/9/2026 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.48% | — | Microsoft Azure ARC | 17/9/2026 | 25/9/2026 | Azure Arc Elevation of Privilege Vulnerability | |
| Aplazada | Crítica (9.1) | 0.77% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips… | |
| Aplazada | Crítica (9.1) | 0.70% | — | ImagerAIPerl Imager File PNGAI | 17/9/2026 | 22/9/2026 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands… | |
| Aplazada | Crítica (9.1) | 0.78% | — | WegiaAI | 17/9/2026 | 18/9/2026 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that… |