Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
8534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | IBM APP Connect EnterpriseAI | 14/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (5.5) | 0.16% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/9/2026 | 7/10/2026 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability… | |
| Pendiente de análisis | Alta (8.6) | 1.3% | — | Puppet EnterpriseAI | 11/9/2026 | 18/9/2026 | Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization.… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| En análisis | Alta (8.8) | 0.15% | — | IBM Aspera Enterprise WebappsAI | 10/9/2026 | 11/9/2026 | IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM APP Connect Enterprise | 10/9/2026 | 16/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization. | |
| Aplazada | Media (5.4) | 0.23% | 💥 PoC | Fairsketch Rise CRMAI | 10/9/2026 | 22/9/2026 | FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and… | |
| Pendiente de análisis | Alta (7.1) | 0.34% | — | Hashicorp ConsulAIHashicorp Consul EnterpriseAI | 10/9/2026 | 10/9/2026 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names,… | |
| Pendiente de análisis | Media (5.4) | 0.31% | — | Hashicorp ConsulAIHashicorp Consul EnterpriseAI | 10/9/2026 | 10/9/2026 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes imported from a… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Hashicorp ConsulAIHashicorp Consul EnterpriseAI | 10/9/2026 | 10/9/2026 | Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue without holding a valid ACL token. This… | |
| Pendiente de análisis | Alta (8.3) | 0.37% | — | Hashicorp ConsulAIHashicorp Consul EnterpriseAI | 10/9/2026 | 10/9/2026 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this… | |
| Pendiente de análisis | Alta (8.5) | 0.23% | — | RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks.… | |
| Pendiente de análisis | Alta (8.3) | 0.39% | — | RenovateAIMend RenovateAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI | 10/9/2026 | 29/9/2026 | Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL… | |
| Aplazada | Media (6.9) | 0.61% | — | Ragic Enterprise Cloud DatabaseAI | 9/9/2026 | 9/9/2026 | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files. | |
| Pendiente de análisis | Alta (7.4) | 0.26% | — | IBM Enterprise Build OF QuarkusAI | 8/9/2026 | 9/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | |
| Analizada | Media (6.5) | 0.29% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. | |
| Analizada | Media (5.5) | 0.09% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 10/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. | |
| Analizada | Media (5.5) | 0.10% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion. |