Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
930 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.13% | — | Rabbitmq Amqp091-goAI | 16/9/2026 | 23/9/2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection.openComplete method in connection.go does not clear those values. Code with… | |
| Pendiente de análisis | Alta (8.2) | 0.41% | — | Rabbitmq Amqp091-goAI | 16/9/2026 | 23/9/2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because validateQos is absent. Values such as -1 therefore wrap to 65535 or 4294967295 instead… | |
| Pendiente de análisis | Crítica (9.4) | 0.28% | — | Rabbitmq Amqp091-goAI | 16/9/2026 | 24/9/2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps… | |
| Pendiente de análisis | Alta (8.7) | 0.10% | — | Rabbitmq Amqp091-goAI | 16/9/2026 | 23/9/2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters with url.Values. If an application accepts a TLS asset path containing ampersand or… | |
| Pendiente de análisis | Alta (8.9) | 0.52% | — | Rabbitmq Amqp091-goAI | 16/9/2026 | 23/9/2026 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore… | |
| Aplazada | Alta (8.3) | 0.36% | — | Zabbix FrontendAI | 13/9/2026 | 24/9/2026 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing… | |
| Pendiente de análisis | Media (5.9) | 0.27% | — | ABB Rtu500AI | 3/9/2026 | 3/9/2026 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of… | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F… | |
| Pendiente de análisis | Media (5.1) | 0.31% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller… | |
| Pendiente de análisis | Ninguna (0) | 0.49% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue… | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 18/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before… | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 18/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through JSONUtil.tryFill, setJavaReturnType,… | |
| Analizada | Media (5.3) | 0.40% | — | Zabbix | 18/8/2026 | 8/9/2026 | An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service. | |
| Analizada | Alta (8.5) | 0.18% | — | Zabbix | 18/8/2026 | 8/9/2026 | Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain. | |
| Analizada | Baja (2.1) | 0.27% | — | Zabbix | 18/8/2026 | 8/9/2026 | The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint. | |
| Analizada | Media (6.9) | 0.17% | — | Zabbix | 18/8/2026 | 8/9/2026 | Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended. | |
| Analizada | Media (5.4) | 0.12% | — | Zabbix | 18/8/2026 | 23/9/2026 | When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by… | |
| Analizada | Baja (2.1) | 0.35% | — | Zabbix | 18/8/2026 | 23/9/2026 | An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service. | |
| Analizada | Media (6) | 0.27% | — | Zabbix | 18/8/2026 | 23/9/2026 | The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. | |
| Analizada | Media (6.8) | 0.34% | — | Zabbix | 18/8/2026 | 23/9/2026 | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss. | |
| Analizada | Media (5.1) | 0.36% | — | Zabbix | 18/8/2026 | 23/9/2026 | An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service. | |
| Analizada | Alta (7.7) | 0.36% | — | Zabbix | 18/8/2026 | 23/9/2026 | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies,… | |
| Analizada | Media (5.3) | 0.23% | — | Zabbix | 18/8/2026 | 23/9/2026 | The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. | |
| Aplazada | Alta (8.1) | 0.49% | — | TabbyAITabby-sshAITabby-electronAI | 10/8/2026 | 9/9/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary… |