Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

5082 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.40%—Vmware Spring Security27/8/20261/9/2026
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security…
AnalizadaMedia (6.1)0.28%—Vmware Spring Security27/8/20262/9/2026
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
AplazadaMedia (6.6)0.28%—Wpmudev Defender SecurityAI27/8/202628/8/2026
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Pendiente de análisisAlta (7.5)0.13%—Vanderbilt Industries Acre Security Spc5300AIVanderbilt Industries Main BoardAI26/8/20269/9/2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
Pendiente de análisisAlta (7.5)0.24%—Vanderbilt Industries Acre Security Spc5300AIVanderbilt Industries SPC Connect PROAI26/8/20269/9/2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
Pendiente de análisisAlta (7.5)0.26%—Vanderbilt Industries Acre Security Spc5300.000AIVanderbilt Industries Acre SecurityAI26/8/20269/9/2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.
AnalizadaMedia (6.5)0.15%—Vmware Spring Security26/8/20264/9/2026
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 -…
AnalizadaAlta (7.4)0.36%—Vmware Spring Security26/8/20264/9/2026
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18
AplazadaAlta (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI26/8/202626/8/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
AnalizadaAlta (7.4)0.39%—Vmware Spring Security25/8/202624/9/2026
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server…
AplazadaCrítica (9.3)2.0%—4mosan Security Technology 4mosan GCB DoctorAI24/8/202626/8/2026
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
AplazadaAlta (8.8)0.59%—Security HardenerAI23/8/202624/8/2026
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every…
AplazadaCrítica (9.3)0.40%—Cleantalk Security AND Malware ScanAI20/8/202620/8/2026
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
AnalizadaMedia (5.3)0.39%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and…
AnalizadaAlta (8.8)0.42%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to…
AnalizadaAlta (8.1)0.35%—Splunk Enterprise Security19/8/202625/8/2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through…
AnalizadaAlta (8.1)0.40%—Splunk Enterprise Security19/8/202625/8/2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the…
AplazadaCrítica (9.1)0.40%—Trueview T18061 Wifi 3MP Robot Pan-tilt Security CameraAI17/8/202631/8/2026
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
AnalizadaCrítica (9.4)2.8%—Tenable Security Center14/8/202619/8/2026
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
AnalizadaCrítica (9.4)9.9%💥 ExploitTenable Security Center14/8/202619/8/2026
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
AnalizadaAlta (7.1)0.32%—Tenable Security Center14/8/202619/8/2026
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
AnalizadaAlta (8.7)1.6%💥 PoCTenable Security Center14/8/202619/8/2026
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
AnalizadaMedia (5.3)0.30%—Tenable Security Center14/8/202619/8/2026
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
AnalizadaMedia (6)0.26%—Tenable Security Center14/8/202619/8/2026
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.
AnalizadaAlta (8.5)0.19%—Tenable Security Center14/8/202619/8/2026
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.