Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
5404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.44% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in… | |
| Aplazada | Crítica (9.3) | 0.37% | 💥 PoC | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns es un resolvedor de RethinkDNS que se despliega en Cloudflare Workers, Deno Deploy, Fastly y Fly.io. Las versiones hasta e incluyendo la 0.1.30 tienen una vulnerabilidad donde la Acción de GitHub pr.yml interpola de manera insegura entrada no confiable, específicamente… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Westerndigital MY CloudAI | 29/9/2025 | 17/6/2026 | An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST. | |
| Aplazada | Alta (7.5) | 0.69% | — | Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI | 29/9/2025 | 17/6/2026 | Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. Attack Vector: Remote, unauthenticated. Severity:… | |
| Aplazada | Alta (8.1) | 0.80% | — | Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI | 29/9/2025 | 17/6/2026 | VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important.… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Aplazada | Baja (2.1) | 0.46% | — | Kodcloud KodboxAI | 26/9/2025 | 17/6/2026 | A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path leads to path traversal. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Alta (7.1) | 0.12% | — | W3S Cloud Technology W3scloud Contact Form 7 TO Zoho CRMAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2. | |
| Analizada | Baja (2.1) | 0.32% | — | Iocoder Yudao-cloud | 26/9/2025 | 17/6/2026 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component HTTP Request Handler. This manipulation of the argument contactId causes improper authorization. It is possible to initiate the attack remotely.… | |
| Analizada | Media (6.7) | 0.46% | — | Dell Cloud Disaster Recovery | 25/9/2025 | 17/6/2026 | Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Aikaan Cloud ControllerAI | 22/9/2025 | 17/6/2026 | AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the controller sends this same static private key to the target device. The device… | |
| Aplazada | Baja (2.9) | 0.38% | — | Cloudflare Vite PluginAI | 19/9/2025 | 17/6/2026 | The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars.… | |
| Aplazada | Baja (1.9) | 0.14% | — | Creality Cloud APPAI | 19/9/2025 | 17/6/2026 | A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack… | |
| Aplazada | Baja (1.8) | 0.12% | — | Softiron HypercloudAI | 18/9/2025 | 30/9/2026 | SoftIron HyperCloud 2.5.0 hasta 2.6.3 puede añadir incorrectamente claves SSH de usuario a las claves autorizadas a nivel de administrador bajo ciertas condiciones, permitiendo una escalada de privilegios no autorizada a administrador vía SSH. Afecta a compilaciones de depuración no productivas y de desarrollo interno… | |
| Aplazada | Alta (8.7) | 0.95% | — | N-partner N-reporterAIN-partner N-cloudAIN-partner N-probeAI | 17/9/2025 | 17/6/2026 | El N-Reporter, N-Cloud y N-Probe desarrollados por N-Partner tienen una vulnerabilidad de inyección de comandos del sistema operativo, permitiendo a atacantes remotos autenticados inyectar comandos arbitrarios del sistema operativo y ejecutarlos en el servidor. | |
| Modificada | Crítica (9.8) | 0.82% | — | Tduckcloud Tduck | 16/9/2025 | 4/8/2026 | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module | |
| Modificada | Alta (8.7) | 0.92% | — | Cloud Jasperreports IOCloud Jasperreports LibraryCloud Jasperreports ServerCloud Jasperreports Studio+1 | 16/9/2025 | 17/6/2026 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library | |
| Aplazada | Crítica (10) | 3.5% | 💥 Exploit | Vmware Cloud GatewayAIVmware BootAIVmware WebfluxAI | 16/9/2025 | 17/6/2026 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Yudao-cloud | 12/9/2025 | 17/6/2026 | A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument ids/newOwnerUserId can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Yudao-cloud | 12/9/2025 | 30/9/2026 | Una vulnerabilidad fue detectada en YunaiV yudao-cloud hasta 2025.09. Este problema afecta a algún procesamiento desconocido del archivo /crm/receivable/submit. La manipulación del argumento ID resulta en autorización indebida. El ataque puede ser ejecutado remotamente. El exploit es ahora público y puede ser usado.… | |
| Analizada | Baja (2.1) | 0.46% | — | Kodcloud Kodbox | 10/9/2025 | 25/9/2026 | Se ha detectado una vulnerabilidad de seguridad en kalcaddle kodbox 1.61. Esto afecta a la función fileGet/fileSave del archivo app/controller/explorer/editor.class.php. La manipulación del argumento path conduce a salto de ruta. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente y puede… | |
| Analizada | Alta (8.8) | 1.2% | — | Fit2cloud 1panel | 10/9/2025 | 17/6/2026 | Vulnerabilidad de inyección de comandos del sistema operativo en la función OperateSSH en 1panel 2.0.8 que permite a los atacantes ejecutar comandos arbitrarios a través del parámetro operation al endpoint /api/v2/hosts/ssh/operate. | |
| Aplazada | Media (6.3) | 0.39% | — | Solax CloudAI | 10/9/2025 | 17/6/2026 | It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle. | |
| Aplazada | Media (6.3) | 0.34% | — | Solax CloudAI | 10/9/2025 | 17/6/2026 | It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system. | |
| Aplazada | Media (5.8) | 0.28% | — | Solax CloudAISolax Solarpanel InverterAI | 10/9/2025 | 17/6/2026 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known. |