Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

14.266 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.42%—Apache Airflow12/8/202616/9/2026
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces…
ModificadaMedia (5.4)0.34%—Apache Airflow12/8/202616/9/2026
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When…
AnalizadaAlta (8.8)0.61%—Apache Airflow12/8/202616/9/2026
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not…
AnalizadaAlta (7.3)0.78%—Apache Airflow12/8/202616/9/2026
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module…
AnalizadaMedia (6.5)0.39%—Apache Airflow12/8/202616/9/2026
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped…
ModificadaMedia (6.5)0.23%—Apache Airflow12/8/202616/9/2026
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that…
AnalizadaMedia (5.4)0.53%—Apache Airflow12/8/202616/9/2026
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on…
ModificadaAlta (8.8)0.48%—Apache Airflow12/8/202616/9/2026
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author…
AnalizadaMedia (4.3)0.42%—Apache Airflow12/8/202616/9/2026
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the…
AnalizadaMedia (5.5)0.15%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux12/8/20261/9/2026
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the…
AplazadaBaja (3)0.17%—Aimeos PagibleAI12/8/20269/9/2026
In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request…
AnalizadaMedia (6.5)0.60%—Apache-airflow-providers-google12/8/202616/9/2026
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a…
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
AplazadaAlta (8.8)0.66%—AcymailingAI11/8/202612/8/2026
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
Pendiente de análisisAlta (7.7)0.63%—Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home…
AnalizadaCrítica (10)1.2%—Adobe Campaign11/8/202628/8/2026
Adobe Campaign Classic (ACC) se ve afectado por una vulnerabilidad de autorización incorrecta que podría provocar la ejecución de código arbitrario en el contexto del usuario actual. Un atacante podría explotar esta vulnerabilidad para ejecutar código arbitrario. La explotación de este problema no requiere la…
AnalizadaCrítica (9)0.78%—Adobe Campaign11/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on…
AnalizadaCrítica (10)1.2%—Adobe Campaign11/8/202628/8/2026
Adobe Campaign Classic (ACC) se ve afectado por una vulnerabilidad de autorización incorrecta que podría provocar la ejecución de código arbitrario en el contexto del usuario actual. Un atacante podría explotar esta vulnerabilidad para ejecutar código arbitrario. La explotación de este problema no requiere la…
En análisisMedia (5.4)0.16%—Intel AI Reference ModelsAI11/8/202612/8/2026
Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially…
En análisisMedia (5.4)0.16%—Intel AI ContainersAI11/8/202612/8/2026
Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via…
AnalizadaMedia (4.6)0.30%—Intel Trust Domain Extensions Guest11/8/202618/8/2026
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local…
AnalizadaMedia (4.6)0.15%—Intel Trust Domain Extensions Guest11/8/202618/8/2026
Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local…
AnalizadaMedia (5.4)0.16%—Intel Gaudi Container Runtime11/8/20261/10/2026
Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local…
Pendiente de análisisMedia (5.7)0.07%—Intel Trust Domain ExtensionsAI11/8/202629/9/2026
Verificación insuficiente de la autenticidad de los datos para algunas Extensiones de Dominio de Confianza Intel(R) (Intel(R) TDX) dentro del Anillo 0: Hipervisor puede permitir una revelación de información. Un adversario de software de sistema con acceso de usuario privilegiado combinado con un ataque de alta…