Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

5404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.44%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in…
AplazadaCrítica (9.3)0.37%💥 PoCRekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+130/9/202517/6/2026
serverless-dns es un resolvedor de RethinkDNS que se despliega en Cloudflare Workers, Deno Deploy, Fastly y Fly.io. Las versiones hasta e incluyendo la 0.1.30 tienen una vulnerabilidad donde la Acción de GitHub pr.yml interpola de manera insegura entrada no confiable, específicamente…
AplazadaCrítica (9.3)1.1%—Westerndigital MY CloudAI29/9/202517/6/2026
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system commands via a specially crafted HTTP POST.
AplazadaAlta (7.5)0.69%—Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI29/9/202517/6/2026
Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. Attack Vector: Remote, unauthenticated. Severity:…
AplazadaAlta (8.1)0.80%—Vmware NSXAIVmware Nsx-tAIVmware Cloud FoundationAI29/9/202517/6/2026
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important.…
AnalizadaAlta (7.8)8.4%⚠ Explotación activa💥 PoCVmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+429/9/202517/6/2026
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the…
AplazadaBaja (2.1)0.46%—Kodcloud KodboxAI26/9/202517/6/2026
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path leads to path traversal. The attack may be performed from remote. The exploit has been disclosed…
AplazadaAlta (7.1)0.12%—W3S Cloud Technology W3scloud Contact Form 7 TO Zoho CRMAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho allows Stored XSS.This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through <= 3.2.
AnalizadaBaja (2.1)0.32%—Iocoder Yudao-cloud26/9/202517/6/2026
A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component HTTP Request Handler. This manipulation of the argument contactId causes improper authorization. It is possible to initiate the attack remotely.…
AnalizadaMedia (6.7)0.46%—Dell Cloud Disaster Recovery25/9/202517/6/2026
Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AplazadaCrítica (9.8)0.42%—Aikaan Cloud ControllerAI22/9/202517/6/2026
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the controller sends this same static private key to the target device. The device…
AplazadaBaja (2.9)0.38%—Cloudflare Vite PluginAI19/9/202517/6/2026
The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars.…
AplazadaBaja (1.9)0.14%—Creality Cloud APPAI19/9/202517/6/2026
A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack…
AplazadaBaja (1.8)0.12%—Softiron HypercloudAI18/9/202530/9/2026
SoftIron HyperCloud 2.5.0 hasta 2.6.3 puede añadir incorrectamente claves SSH de usuario a las claves autorizadas a nivel de administrador bajo ciertas condiciones, permitiendo una escalada de privilegios no autorizada a administrador vía SSH. Afecta a compilaciones de depuración no productivas y de desarrollo interno…
AplazadaAlta (8.7)0.95%—N-partner N-reporterAIN-partner N-cloudAIN-partner N-probeAI17/9/202517/6/2026
El N-Reporter, N-Cloud y N-Probe desarrollados por N-Partner tienen una vulnerabilidad de inyección de comandos del sistema operativo, permitiendo a atacantes remotos autenticados inyectar comandos arbitrarios del sistema operativo y ejecutarlos en el servidor.
ModificadaCrítica (9.8)0.82%—Tduckcloud Tduck16/9/20254/8/2026
SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module
ModificadaAlta (8.7)0.92%—Cloud Jasperreports IOCloud Jasperreports LibraryCloud Jasperreports ServerCloud Jasperreports Studio+116/9/202517/6/2026
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
AplazadaCrítica (10)3.5%💥 ExploitVmware Cloud GatewayAIVmware BootAIVmware WebfluxAI16/9/202517/6/2026
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true:
AnalizadaBaja (2.1)0.33%—Iocoder Yudao-cloud12/9/202517/6/2026
A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument ids/newOwnerUserId can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and…
AnalizadaBaja (2.1)0.33%—Iocoder Yudao-cloud12/9/202530/9/2026
Una vulnerabilidad fue detectada en YunaiV yudao-cloud hasta 2025.09. Este problema afecta a algún procesamiento desconocido del archivo /crm/receivable/submit. La manipulación del argumento ID resulta en autorización indebida. El ataque puede ser ejecutado remotamente. El exploit es ahora público y puede ser usado.…
AnalizadaBaja (2.1)0.46%—Kodcloud Kodbox10/9/202525/9/2026
Se ha detectado una vulnerabilidad de seguridad en kalcaddle kodbox 1.61. Esto afecta a la función fileGet/fileSave del archivo app/controller/explorer/editor.class.php. La manipulación del argumento path conduce a salto de ruta. El ataque puede iniciarse remotamente. El exploit ha sido divulgado públicamente y puede…
AnalizadaAlta (8.8)1.2%—Fit2cloud 1panel10/9/202517/6/2026
Vulnerabilidad de inyección de comandos del sistema operativo en la función OperateSSH en 1panel 2.0.8 que permite a los atacantes ejecutar comandos arbitrarios a través del parámetro operation al endpoint /api/v2/hosts/ssh/operate.
AplazadaMedia (6.3)0.39%—Solax CloudAI10/9/202517/6/2026
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
AplazadaMedia (6.3)0.34%—Solax CloudAI10/9/202517/6/2026
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.
AplazadaMedia (5.8)0.28%—Solax CloudAISolax Solarpanel InverterAI10/9/202517/6/2026
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.