Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

18.391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.38%—Mikrotik RouterosAI14/9/202624/9/2026
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path…
Pendiente de análisisMedia (5.3)0.49%—Mikrotik RouterosAI14/9/202624/9/2026
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write…
AnalizadaAlta (8.2)0.35%—Microsoft Windows 11 26h114/9/202629/9/2026
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.20%—Microsoft Edge Chromium14/9/202625/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Pendiente de análisisCrítica (9.8)0.62%💥 PoCXbifrost BifrostAI14/9/202618/9/2026
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One…
Pendiente de análisisMedia (4.3)0.44%—Microsoft VscodeAIOvsxAI14/9/202616/9/2026
Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}/{path}, WebResourceService opened the entry with ZipFile.getInputStream() and passed…
AplazadaAlta (8.7)0.55%—Conprosys HMI SystemAI14/9/202616/9/2026
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
AplazadaMedia (4.1)0.18%—Conprosys Nano SeriesAI14/9/202616/9/2026
Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.
AplazadaMedia (5.3)0.46%—Conprosys Nano SeriesAI14/9/202616/9/2026
Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
AplazadaMedia (5.1)0.24%—Conprosys Nano SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)0.61%—Conprosys TM SeriesAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
AplazadaAlta (8.7)1.9%—Conprosys TM SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.3)0.45%—Conprosys PAC SeriesAI14/9/202616/9/2026
An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
AplazadaAlta (8.7)1.9%—Conprosys PAC SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.26%—Conprosys PAC SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (5.3)0.45%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.
AplazadaAlta (8.7)1.9%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.26%—Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaBaja (3.5)0.26%—SEP SesamAIMicrosoft Active DirectoryAI12/9/202622/9/2026
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for…
AnalizadaMedia (6.1)0.41%—Microsoft Edge Chromium11/9/202625/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.66%—Microsoft EdgeMicrosoft Edge Chromium11/9/20266/10/2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Pendiente de análisisMedia (6.9)0.13%—Microsoft Windows 8AISilabs Cp210x DriverAI10/9/202610/9/2026
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.
Pendiente de análisisAlta (7.5)0.32%—Eprosima Fast DDSAI9/9/202614/9/2026
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast…
Pendiente de análisisCrítica (9.1)0.38%—Eprosima Fast DDSAI9/9/20269/9/2026
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG`…
AnalizadaAlta (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.