Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.59%—TON BlockchainAITON Virtual MachineAI13/2/202617/6/2026
A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a malicious…
AplazadaAlta (8.4)0.14%—OKI Electric Industry OKI ProductsAIRicoh ProductsAIMurata Machinery Murata ProductsAI9/2/202617/6/2026
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
AnalizadaMedia (4.5)0.25%—Oracle Java Virtual Machine20/1/202617/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 and 21.3-21.20. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Java VM. Successful attacks require…
AplazadaAlta (8.5)0.15%—Emerson PAC Machine EditionAI13/1/202617/6/2026
Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem…
AnalizadaAlta (7.8)0.32%—Microsoft Azure Connected Machine Agent13/1/202617/6/2026
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
ModificadaAlta (8.6)0.49%💥 PoCSemantic-machines Veda13/1/20265/7/2026
An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.
AplazadaCrítica (9)1.3%💥 ExploitEclipse CHEAIEclipse Che-machine-execAI13/1/202621/9/2026
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
AnalizadaMedia (6.1)0.25%—Simplemachines Simple Machines Forum18/12/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
AplazadaAlta (8.8)0.53%—Semantic-machines VedaAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2.
AnalizadaMedia (5.9)0.23%—Oracle Java Virtual Machine21/10/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can…
AnalizadaAlta (7.8)0.57%—Microsoft Azure Connected Machine Agent14/10/202517/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.56%—Microsoft Azure Connected Machine Agent14/10/202517/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.37%—Microsoft Azure Connected Machine Agent9/9/202517/6/2026
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.35%—Microsoft Azure Connected Machine Agent9/9/20251/10/2026
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.27%—Nomachine2/9/202517/6/2026
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (8.8)0.68%—Microsoft Azure Machine Learning18/7/202517/6/2026
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.73%—Microsoft Azure Machine Learning18/7/202517/6/2026
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.64%—Microsoft Azure Machine Learning18/7/202517/6/2026
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.7)0.35%—Oracle Java Virtual Machine15/7/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. While the…
AplazadaAlta (7)0.25%—Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI14/7/202517/6/2026
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
AnalizadaAlta (8.8)0.97%—Microsoft Azure Machine Learning30/4/202517/6/2026
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.4)0.37%—Oracle Java Virtual Machine15/4/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability…
AnalizadaAlta (7.8)0.88%—Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+18/4/202517/6/2026
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
AplazadaMedia (6.1)0.32%—WP Time MachineAI2/4/202517/6/2026
The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the 'wpTimeMachineCore.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
ModificadaMedia (5.1)0.41%—Simplemachines Simple Machines Forum21/3/202517/6/2026
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation of the argument subject/message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the…