Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 302 respecto a la semana anterior
Críticas / altas1389▼ 21 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
39.978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | — | — | Microsoft MsquicAI | 6/10/2026 | 6/10/2026 | MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can… | |
| Aplazada | Crítica (9.1) | — | — | Microsoft UFOAI | 6/10/2026 | 6/10/2026 | Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote… | |
| Pendiente de análisis | Crítica (9.6) | — | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 7/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Pendiente de análisis | Crítica (9.1) | — | — | Oracle VirtualboxAI | 6/10/2026 | 6/10/2026 | Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model. | |
| Aplazada | Crítica (9.3) | — | — | MooncakeAI | 6/10/2026 | 6/10/2026 | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or… | |
| Pendiente de análisis | Crítica (9.2) | — | 💥 PoC | SmartyAI | 6/10/2026 | 6/10/2026 | Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the… | |
| Aplazada | Crítica (9.1) | — | — | PlankaAI | 6/10/2026 | 6/10/2026 | PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full… | |
| Recibida | Crítica (9.8) | 0.17% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: A remote peer can craft an RDMA-Write/Read RETH so… | |
| Recibida | Crítica (9.8) | 0.18% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to… | |
| Aplazada | Crítica (9.3) | 0.33% | — | Armember PremiumAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | |
| Aplazada | Crítica (9.3) | 0.25% | — | PortoAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | |
| Aplazada | Crítica (9.3) | 0.25% | — | User Subscriptions FormAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Data443 Gdpr FrameworkAI | 6/10/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Sendpress NewslettersAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Gmedia Photo GalleryAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | |
| Aplazada | Crítica (10) | 0.29% | — | Doctreat CoreAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | |
| Aplazada | Crítica (10) | 0.42% | — | DoctreatAI | 6/10/2026 | 6/10/2026 | Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Radiustheme Radius BookingAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Metabox Meta BOX AIOAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Amentotech WorkreapAI | 6/10/2026 | 6/10/2026 | Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | TaskbotAI | 6/10/2026 | 6/10/2026 | Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. | |
| Aplazada | Crítica (9.9) | 0.45% | — | WP DuplicateAI | 6/10/2026 | 6/10/2026 | Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. | |
| Aplazada | Crítica (9.8) | 0.45% | — | TaskbotAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Fs-code BookneticAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | |
| Aplazada | Crítica (10) | 0.49% | — | Kognetiks ChatbotAI | 6/10/2026 | 6/10/2026 | Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions. |