Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 302 respecto a la semana anterior
Críticas / altas1389▼ 21 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

39.978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.1)——Microsoft MsquicAI6/10/20266/10/2026
MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can…
AplazadaCrítica (9.1)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote…
Pendiente de análisisCrítica (9.6)——Progress Software Autonomous Rest Connector Genai AgentsAI6/10/20267/10/2026
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user…
Pendiente de análisisCrítica (9.1)——Oracle VirtualboxAI6/10/20266/10/2026
Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model.
AplazadaCrítica (9.3)——MooncakeAI6/10/20266/10/2026
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or…
Pendiente de análisisCrítica (9.2)—💥 PoCSmartyAI6/10/20266/10/2026
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the…
AplazadaCrítica (9.1)——PlankaAI6/10/20266/10/2026
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full…
RecibidaCrítica (9.8)0.17%—Linux KernelAI6/10/20267/10/2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: A remote peer can craft an RDMA-Write/Read RETH so…
RecibidaCrítica (9.8)0.18%—Linux KernelAI6/10/20267/10/2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to…
AplazadaCrítica (9.3)0.33%—Armember PremiumAI6/10/20266/10/2026
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
AplazadaCrítica (9.3)0.25%—PortoAI6/10/20266/10/2026
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
AplazadaCrítica (9.3)0.25%—User Subscriptions FormAI6/10/20266/10/2026
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
AplazadaCrítica (9.8)0.34%—Data443 Gdpr FrameworkAI6/10/20266/10/2026
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
AplazadaCrítica (9.3)0.33%—Sendpress NewslettersAI6/10/20266/10/2026
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
AplazadaCrítica (9.3)0.25%—Gmedia Photo GalleryAI6/10/20266/10/2026
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
AplazadaCrítica (10)0.29%—Doctreat CoreAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
AplazadaCrítica (10)0.42%—DoctreatAI6/10/20266/10/2026
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
AplazadaCrítica (9.3)0.30%—Radiustheme Radius BookingAI6/10/20266/10/2026
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
AplazadaCrítica (9.8)0.48%—Metabox Meta BOX AIOAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
AplazadaCrítica (9.9)0.48%—Amentotech WorkreapAI6/10/20266/10/2026
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
AplazadaCrítica (9.9)0.48%—TaskbotAI6/10/20266/10/2026
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
AplazadaCrítica (9.9)0.45%—WP DuplicateAI6/10/20266/10/2026
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
AplazadaCrítica (9.8)0.45%—TaskbotAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
AplazadaCrítica (9.3)0.38%—Fs-code BookneticAI6/10/20266/10/2026
Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions.
AplazadaCrítica (10)0.49%—Kognetiks ChatbotAI6/10/20266/10/2026
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Orbitaley — Vulnerabilidades