Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

40.079 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.71%—VM2AI18/9/202618/9/2026
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps…
AplazadaCrítica (10)0.73%—VM2 NodevmAI18/9/202621/9/2026
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit…
AplazadaCrítica (10)0.73%—VM2AI18/9/202622/9/2026
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`,…
AplazadaCrítica (9.1)0.65%—ImagerAI18/9/202618/9/2026
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for…
AplazadaCrítica (9.2)0.29%—ABB Freelance Controller DCPAIABB Freelance Controller Ac700AIABB Freelance Controller Ac800AIABB Freelance Controller Ac900AI18/9/202618/9/2026
Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance…
AplazadaCrítica (9.4)0.34%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full…
AplazadaCrítica (9.4)0.67%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex…
Pendiente de análisisCrítica (9.8)0.60%—Synology Diskstation ManagerAI18/9/202618/9/2026
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Pendiente de análisisCrítica (9.8)0.66%—Synology Diskstation ManagerAI18/9/202618/9/2026
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
AnalizadaCrítica (9.8)0.47%—Hcltech Bigfix Service Management18/9/20268/10/2026
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile…
AplazadaCrítica (9.1)0.82%—AF CompanionAI18/9/202618/9/2026
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
AplazadaCrítica (9.3)0.91%—Hgiga OakloudsAI18/9/202618/9/2026
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
AnalizadaCrítica (9.9)0.78%—Microsoft Azure Horizondb17/9/202625/9/2026
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Fabric17/9/202625/9/2026
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.33%—Microsoft Azure Billing17/9/20267/10/2026
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.6)0.79%—Microsoft Azure Cosmos DB17/9/202629/9/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.67%—Microsoft Azure AI Foundry17/9/202625/9/2026
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.1)0.44%—Microsoft Azure Logic Apps17/9/202625/9/2026
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.60%—Microsoft Azure Logic Apps17/9/202625/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.53%—Microsoft Azure ARC17/9/202625/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.80%—Microsoft Azure Container Registry17/9/202629/9/2026
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.48%—Microsoft Azure ARC17/9/202625/9/2026
Azure Arc Elevation of Privilege Vulnerability
AplazadaCrítica (9.1)0.77%—Alembic ASH AuthenticationAI17/9/202618/9/2026
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips…
AplazadaCrítica (9.1)0.70%—ImagerAIPerl Imager File PNGAI17/9/202622/9/2026
Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands…
AplazadaCrítica (9.1)0.78%—WegiaAI17/9/202618/9/2026
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that…
Orbitaley — Vulnerabilidades