Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

14.266 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.56%—IBM ViosIBM AIX20/8/202625/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
AnalizadaAlta (7.8)0.09%—IBM ViosIBM AIX20/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.
AnalizadaAlta (7.5)0.55%—IBM ViosIBM AIX20/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
AnalizadaAlta (7.8)0.08%—IBM ViosIBM AIX20/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
AnalizadaAlta (7)0.10%—IBM ViosIBM AIX20/8/202624/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
AplazadaMedia (5.9)0.40%—AiosmtplibAI20/8/202618/9/2026
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the…
Pendiente de análisisCrítica (9.8)1.7%—NEO MJSAIAI MCPAI20/8/20263/9/2026
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution…
AplazadaCrítica (9.3)0.40%—Locatoraid Store LocatorAI20/8/202620/8/2026
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
AplazadaMedia (6.5)0.33%—AltairAI20/8/20265/10/2026
Control de acceso roto no autenticado en versiones de Altair menor o igual a 5.2.2.
AplazadaMedia (5.3)0.46%—Siteground AI AgentAI20/8/202620/8/2026
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress…
AnalizadaAlta (8.1)0.35%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is…
AnalizadaMedia (4.3)0.25%—Splunk AI Toolkit19/8/202624/8/2026
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history…
AnalizadaAlta (8.1)0.35%—Splunk AI Toolkit19/8/202621/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes…
AnalizadaAlta (7.5)0.32%—Splunk AI Toolkit19/8/202621/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as…
AnalizadaAlta (8.8)0.65%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix…
AnalizadaAlta (8.3)0.35%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because…
AnalizadaMedia (5.9)0.18%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk…
AnalizadaMedia (5.4)0.23%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container…
En análisisAlta (8.3)0.47%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege…
AnalizadaCrítica (9.8)0.80%—IBM AIXIBM Vios19/8/202627/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
AnalizadaCrítica (9.8)0.80%—IBM ViosIBM AIX19/8/202621/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
AnalizadaMedia (6.7)0.17%—IBM ViosIBM AIX19/8/202621/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
AnalizadaCrítica (9.8)0.80%—IBM ViosIBM AIX19/8/202621/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
AnalizadaAlta (8.8)0.75%—IBM ViosIBM AIX19/8/202621/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
AnalizadaAlta (8.8)0.42%—IBM ViosIBM AIX19/8/202621/8/2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.