Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Aplazada | Alta (8.7) | 0.57% | — | DevtronAI | 31/8/2026 | 8/9/2026 | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve… | |
| Aplazada | Alta (7) | 0.17% | — | Electron-builderAIMicrosoft Windows InstallerAI | 30/8/2026 | 1/9/2026 | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that… | |
| Aplazada | Alta (8.6) | 0.45% | — | Iflytek Astron-agentAI | 29/8/2026 | 10/9/2026 | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions. | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAIMind ElixirAIElectronAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a… | |
| Analizada | Media (6.8) | 0.26% | — | Lutzroeder Netron | 27/8/2026 | 1/9/2026 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | |
| Analizada | Media (6.8) | 0.26% | — | Lutzroeder Netron | 27/8/2026 | 29/9/2026 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | |
| Analizada | Media (6.8) | 0.26% | — | Lutzroeder Netron | 27/8/2026 | 29/9/2026 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | |
| Aplazada | Media (5.5) | 0.59% | — | Boxpositron With-context-mcpAI | 27/8/2026 | 28/8/2026 | A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used.… | |
| Aplazada | Media (5.3) | 0.34% | — | Murrelektronik XelityAI | 24/8/2026 | 3/9/2026 | The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can… | |
| Aplazada | Alta (7.5) | 0.42% | — | StrongswanAI | 22/8/2026 | 9/9/2026 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. | |
| Pendiente de análisis | Alta (7.4) | 0.56% | — | Wildfly ElytronAI | 20/8/2026 | 21/9/2026 | A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include… | |
| Aplazada | Alta (8.3) | 0.41% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs… | |
| Aplazada | Alta (8.8) | 0.20% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler… | |
| Aplazada | Alta (7.8) | 0.22% | — | Super ProductivityAIElectronAI | 18/8/2026 | 18/9/2026 | Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The electron/preload.ts… | |
| Aplazada | Alta (8.1) | 0.49% | — | TabbyAITabby-sshAITabby-electronAI | 10/8/2026 | 9/9/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary… | |
| Aplazada | Alta (7.1) | 0.26% | — | Telefunken Te24553b45v2dzAIVestel Mb181AIVestel Voltron181AITivo OSAI | 7/8/2026 | 28/8/2026 | An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended… | |
| Pendiente de análisis | Media (5.6) | 0.11% | — | Elan Microelectronics Corp Elan Smart-padAIElan Microelectronics Corp Etd.sysAIElan Microelectronics Corp Etdsmbus.sysAI | 6/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where… | |
| En análisis | Media (5.4) | 0.44% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered… | |
| En análisis | Media (6.9) | 0.18% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the… | |
| En análisis | Media (5.4) | 0.58% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks… | |
| En análisis | Media (5.7) | 0.55% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their… | |
| En análisis | Alta (7.2) | 0.45% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user interaction because new-window navigations taking… |