Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

5404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.36%—Apache Cloudstack27/11/202517/6/2026
In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResourceDetails - listVirtualMachinesUsageHistory - listVolumesUsageHistory While these APIs were accessible only to authorized users, insufficient permission validation meant that users could occasionally…
AnalizadaMedia (4.7)0.46%—Apache Cloudstack27/11/202517/6/2026
In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. This issue affects Apache CloudStack: from 4.18.0 before 4.20.2, from 4.21.0 before 4.22.0. Users are recommended to upgrade to versions 4.20.2 or 4.22.0,…
AplazadaCrítica (9.3)0.68%—Malion Security PointAIMalioncloudAI25/11/202517/6/2026
Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.
AplazadaCrítica (9.3)0.68%—Malion Security PointAIMalioncloudAI25/11/202517/6/2026
Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HTTP headers. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.
AplazadaMedia (6)0.39%—Asus AicloudAI25/11/202517/6/2026
An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more…
AplazadaCrítica (9.2)16%—Asus AicloudAISambaAI25/11/202517/6/2026
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization. Refer to the Security Update for ASUS Router Firmware section on the ASUS…
AnalizadaCrítica (9.8)0.37%—Quark Cloud Drive20/11/202517/6/2026
Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory,…
AplazadaMedia (6.8)0.11%—HCL Glovius CloudAI20/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AnalizadaMedia (5.4)0.30%—Magicbug Cloudlog14/11/202517/6/2026
An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a…
AplazadaMedia (5.3)0.27%—Quantumcloud ChatbotAI13/11/20257/10/2026
Vulnerabilidad de autorización faltante en el chatbot QuantumCloud ChatBot permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a ChatBot: desde n/a hasta menor o igual que 7.3.9.
AnalizadaBaja (3.5)0.28%—SplunkSplunk Cloud Platform12/11/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a…
AnalizadaMedia (6.1)0.24%—SplunkSplunk Cloud Platform12/11/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splunk Web login endpoint. When an authenticated user visits the…
AplazadaAlta (8.6)0.35%—Datamosaix Private CloudAI11/11/202517/6/2026
A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website.
AplazadaAlta (7.6)0.15%—Datamosaix Private CloudAI11/11/202517/6/2026
A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period.
AplazadaMedia (6.3)0.16%—Qualys Cloud AgentAI10/11/20257/10/2026
El Agente de Qualys Cloud incluía un script de desinstalación empaquetado (qagent_uninstall.sh), específico para las versiones compatibles con Mac y Linux, que invocaba múltiples comandos del sistema sin usar rutas absolutas y sin sanear el entorno $PATH. Si el script de desinstalación se ejecuta con privilegios…
AplazadaAlta (8.8)0.36%—CloudinaryAI10/11/202517/6/2026
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering…
AnalizadaAlta (8.8)0.40%—Elastic Cloud Enterprise7/11/20257/10/2026
Autorización incorrecta en Elastic Cloud Enterprise puede conducir a Escalada de privilegios donde el usuario 'readonly' integrado puede llamar a APIs que no deberían estar permitidas. La lista de APIs que se ven afectadas por este problema es: post:/platform/configuration/security/service-accounts…
AnalizadaCrítica (9.6)0.38%—Pig4cloud PIG7/11/202517/6/2026
In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who has completed login…
AnalizadaCrítica (9.1)1.1%—Pig4cloud PIG7/11/202517/6/2026
In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through reflection. At this time, the eval method in…
AplazadaMedia (6.5)0.20%—Tagdiv Cloud LibraryAI6/11/20257/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en tagDiv tagDiv Cloud Library td-cloud-library permite XSS basado en DOM. Este problema afecta a tagDiv Cloud Library: desde n/a hasta < 3.9.2.
AnalizadaMedia (5.3)0.95%💥 ExploitOwncloud Guests5/11/202517/6/2026
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a…
AnalizadaMedia (4.4)0.10%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service.
AnalizadaMedia (6.7)0.14%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.