Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
5318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.9) | 0.59% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeline group… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames,… | |
| Pendiente de análisis | Media (4.3) | 0.40% | — | Thoughtworks GocdAI | 21/9/2026 | 25/9/2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise… | |
| Pendiente de análisis | Media (5.1) | 0.71% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent… | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can place URI or HTML… | |
| Pendiente de análisis | Media (5.3) | 0.58% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to retrieve a pipeline template by name… | |
| Aplazada | Media (6.5) | 0.47% | — | Nextcloud Team FoldersAINextcloud WorkspaceAI | 18/9/2026 | 18/9/2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management… | |
| Aplazada | Crítica (9.2) | 0.12% | — | Mitsubishielectric GX Works3AIMitsubishielectric Motion Control SettingAI | 17/9/2026 | 18/9/2026 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby… | |
| Pendiente de análisis | Media (6.5) | 0.56% | — | Cisco Broadworks Commpilot Application SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this… | |
| Aplazada | Alta (8.7) | 0.35% | — | Curiosity WorkspaceAI | 16/9/2026 | 23/9/2026 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or… | |
| Analizada | Media (4.3) | 0.23% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges… | |
| Analizada | Media (5.3) | 0.42% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to… | |
| Analizada | Media (5.5) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system. | |
| Analizada | Media (5.5) | 0.33% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information,… | |
| Analizada | Media (5.5) | 0.38% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially… | |
| Analizada | Media (5.8) | 0.11% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Analizada | Media (5.9) | 0.39% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported… | |
| Analizada | Media (5.9) | 0.46% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service. | |
| Analizada | Media (6.4) | 0.22% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and… | |
| Analizada | Media (6.5) | 4.5% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result… | |
| Analizada | Media (6.5) | 0.46% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to… | |
| Analizada | Media (6.5) | 0.27% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations. | |
| Analizada | Media (6.5) | 0.48% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability… | |
| Analizada | Media (6.6) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system. | |
| Analizada | Alta (7) | 0.36% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways. |