Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

5404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.37%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink.
AnalizadaAlta (7.2)0.33%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.
AnalizadaAlta (8.4)0.65%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system.
AnalizadaCrítica (9.1)0.38%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is…
AnalizadaAlta (7.2)1.0%—Dell Cloudlink5/11/202517/6/2026
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.
AnalizadaMedia (5.4)0.18%—IBM Cloud PAK FOR Business Automation3/11/202517/6/2026
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to…
AnalizadaAlta (7.4)0.27%—IBM Cloud PAK FOR Business Automation3/11/202517/6/2026
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.
AnalizadaMedia (6.5)0.45%—IBM Cloud PAK FOR Business Automation3/11/202517/6/2026
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.
AnalizadaMedia (4.3)0.36%—IBM Cloud PAK FOR Business Automation3/11/202517/6/2026
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
AnalizadaAlta (7.1)0.29%—Fit2cloud Jumpserver30/10/202517/6/2026
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sending crafted messages to the /ws/ldap/ WebSocket endpoint, bypassing…
AnalizadaAlta (8.1)0.50%—Fit2cloud Jumpserver30/10/202517/6/2026
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection API endpoint…
AplazadaBaja (2.1)0.26%—Yonyou U8 CloudAI28/10/20258/10/2026
Se ha encontrado una vulnerabilidad en Yonyou U8 Cloud hasta 5.1sp. El elemento afectado es una función desconocida del archivo /service/NCloudGatewayServlet del componente Gestor de Cabeceras de Solicitud. Dicha manipulación del argumento ts/sign conduce a una subida sin restricciones. El ataque puede realizarse de…
AplazadaAlta (7.1)0.14%—Andrealandonio Cloud-searchAI27/10/20258/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Andrea Landonio CloudSearch cloud-search permite XSS Almacenado. Este problema afecta a CloudSearch: desde n/d hasta menor o igual que 3.0.0.
AplazadaMedia (4.3)0.24%—Quantumcloud ChatbotAI27/10/20258/10/2026
Vulnerabilidad de Autorización Faltante en chatbot QuantumCloud ChatBot permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a ChatBot: desde n/a hasta menor o igual que 7.3.0.
AplazadaCrítica (9.8)0.58%—Quantumcloud KBX PRO UltimateAI22/10/20258/10/2026
Deserialización de Datos No Confiables vulnerabilidad en quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro permite Inyección de Objetos. Este problema afecta a KBx Pro Ultimate: desde n/a hasta menor o igual que 8.0.5.
AplazadaCrítica (9.8)0.73%💥 PoCQuantumcloud Simple Link DirectoryAI22/10/20258/10/2026
Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en quantumcloud Simple Link Directory qc-simple-link-directory permite el abuso de autenticación. Este problema afecta a Simple Link Directory: desde n/a hasta < 14.8.1.
AplazadaAlta (8.7)0.32%—Cloudedge CloudAI21/10/20258/10/2026
La Nube de CloudEdge no sanitiza la entrada del tema MQTT, lo que podría permitir a un atacante aprovechar el comodín MQTT para recibir todos los mensajes que deberían ser entregados a otros usuarios al suscribirse a un tema MQTT. En estos mensajes, el atacante puede obtener las credenciales y la información clave…
AplazadaMedia (6.5)0.53%—Nextcloud TablesAI16/10/202517/6/2026
Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is…
AplazadaAlta (7.5)0.48%—Vmware Cloud Gateway Server WebfluxAI16/10/202517/6/2026
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are true:
AnalizadaAlta (8.7)0.35%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+2015/10/202517/6/2026
When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.37%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1915/10/202517/6/2026
When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (5.6)0.14%—Adobe Creative Cloud15/10/20258/10/2026
Las versiones 6.7.0.278 y anteriores de Creative Cloud Desktop están afectadas por una vulnerabilidad de condición de carrera (TOCTOU) de tiempo de verificación y tiempo de uso que podría conducir a una escritura arbitraria en el sistema de archivos. Un atacante con pocos privilegios podría explotar el momento entre…
AnalizadaAlta (8.7)0.46%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/10/202517/6/2026
When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.44%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR Kubernetes15/10/202517/6/2026
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have…
AnalizadaAlta (8.7)0.35%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1815/10/202517/6/2026
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.