Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
5404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.37% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink. | |
| Analizada | Alta (7.2) | 0.33% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system. | |
| Analizada | Alta (8.4) | 0.65% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system. | |
| Analizada | Crítica (9.1) | 0.38% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is… | |
| Analizada | Alta (7.2) | 1.0% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to… | |
| Analizada | Alta (7.4) | 0.27% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls. | |
| Analizada | Media (6.5) | 0.45% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment. | |
| Analizada | Alta (7.1) | 0.29% | — | Fit2cloud Jumpserver | 30/10/2025 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sending crafted messages to the /ws/ldap/ WebSocket endpoint, bypassing… | |
| Analizada | Alta (8.1) | 0.50% | — | Fit2cloud Jumpserver | 30/10/2025 | 17/6/2026 | JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection API endpoint… | |
| Aplazada | Baja (2.1) | 0.26% | — | Yonyou U8 CloudAI | 28/10/2025 | 8/10/2026 | Se ha encontrado una vulnerabilidad en Yonyou U8 Cloud hasta 5.1sp. El elemento afectado es una función desconocida del archivo /service/NCloudGatewayServlet del componente Gestor de Cabeceras de Solicitud. Dicha manipulación del argumento ts/sign conduce a una subida sin restricciones. El ataque puede realizarse de… | |
| Aplazada | Alta (7.1) | 0.14% | — | Andrealandonio Cloud-searchAI | 27/10/2025 | 8/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Andrea Landonio CloudSearch cloud-search permite XSS Almacenado. Este problema afecta a CloudSearch: desde n/d hasta menor o igual que 3.0.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Quantumcloud ChatbotAI | 27/10/2025 | 8/10/2026 | Vulnerabilidad de Autorización Faltante en chatbot QuantumCloud ChatBot permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a ChatBot: desde n/a hasta menor o igual que 7.3.0. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Quantumcloud KBX PRO UltimateAI | 22/10/2025 | 8/10/2026 | Deserialización de Datos No Confiables vulnerabilidad en quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro permite Inyección de Objetos. Este problema afecta a KBx Pro Ultimate: desde n/a hasta menor o igual que 8.0.5. | |
| Aplazada | Crítica (9.8) | 0.73% | 💥 PoC | Quantumcloud Simple Link DirectoryAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en quantumcloud Simple Link Directory qc-simple-link-directory permite el abuso de autenticación. Este problema afecta a Simple Link Directory: desde n/a hasta < 14.8.1. | |
| Aplazada | Alta (8.7) | 0.32% | — | Cloudedge CloudAI | 21/10/2025 | 8/10/2026 | La Nube de CloudEdge no sanitiza la entrada del tema MQTT, lo que podría permitir a un atacante aprovechar el comodín MQTT para recibir todos los mensajes que deberían ser entregados a otros usuarios al suscribirse a un tema MQTT. En estos mensajes, el atacante puede obtener las credenciales y la información clave… | |
| Aplazada | Media (6.5) | 0.53% | — | Nextcloud TablesAI | 16/10/2025 | 17/6/2026 | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is… | |
| Aplazada | Alta (7.5) | 0.48% | — | Vmware Cloud Gateway Server WebfluxAI | 16/10/2025 | 17/6/2026 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are true: | |
| Analizada | Alta (8.7) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 15/10/2025 | 17/6/2026 | When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.37% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 15/10/2025 | 17/6/2026 | When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.6) | 0.14% | — | Adobe Creative Cloud | 15/10/2025 | 8/10/2026 | Las versiones 6.7.0.278 y anteriores de Creative Cloud Desktop están afectadas por una vulnerabilidad de condición de carrera (TOCTOU) de tiempo de verificación y tiempo de uso que podría conducir a una escritura arbitraria en el sistema de archivos. Un atacante con pocos privilegios podría explotar el momento entre… | |
| Analizada | Alta (8.7) | 0.46% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes | 15/10/2025 | 17/6/2026 | When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR Kubernetes | 15/10/2025 | 17/6/2026 | When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… | |
| Analizada | Alta (8.7) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 15/10/2025 | 17/6/2026 | When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |