Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
8614 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.28% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in version 4.0.260208.0 of… | |
| Analizada | Baja (3) | 0.27% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260206.0… | |
| Analizada | Baja (2.2) | 0.27% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N (2.2 Low). This issue was fixed in version 4.0.260205.0 of the runZero… | |
| Analizada | Media (5.3) | 0.31% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was… | |
| Analizada | Baja (3) | 0.18% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version… | |
| Analizada | Media (6.8) | 0.32% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixed in version… | |
| Analizada | Media (5.9) | 0.34% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (5.9 Medium). This… | |
| Analizada | Baja (2.7) | 0.33% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N (2.7 Low). This… | |
| Analizada | Media (5.8) | 0.33% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed… | |
| Analizada | Alta (8.4) | 0.40% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version 4.0.260202.0 of the… | |
| Analizada | Media (6.4) | 0.34% | — | Runzero Platform | 7/4/2026 | 17/6/2026 | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H (6.4… | |
| Analizada | Alta (7.8) | 0.38% | — | Huggingface Transformers | 7/4/2026 | 17/6/2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library… | |
| Aplazada | Crítica (9.8) | 63% | 💥 Exploit | Ninjaforms Ninja Forms File UploadsAI | 7/4/2026 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Analizada | Baja (2.1) | 0.28% | — | Parseplatform Parse-server | 6/4/2026 | 24/7/2026 | Parse Server es un backend de código abierto que puede ser desplegado en cualquier infraestructura que pueda ejecutar Node.js. Antes de 8.6.73 y 9.7.1-alpha.4, se puede subir un archivo con una extensión de nombre de archivo que pasa la lista de permitidos de extensiones de archivo (por ejemplo, .txt) pero con una… | |
| Analizada | Alta (7.5) | 0.20% | — | Nearform Fast-jwt | 6/4/2026 | 17/6/2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token instead of rejecting… | |
| Analizada | Crítica (9.1) | 0.22% | — | Nearform Fast-jwt | 6/4/2026 | 17/6/2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for different tokens can lead to cache collisions. This could cause tokens to be mis-identified during the verification process leading to valid… | |
| Analizada | Crítica (9.1) | 0.27% | — | Nearform Fast-jwt | 6/4/2026 | 17/6/2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT algorithm confusion attack that CVE-2023-48223 patched. | |
| Analizada | Alta (7.5) | 0.15% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+99 | 6/4/2026 | 17/6/2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca0000 Firmware+19 | 6/4/2026 | 17/6/2026 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcd9375 FirmwareQualcomm Wcd9378c FirmwareQualcomm Wcd9380 FirmwareQualcomm Wcd9385 Firmware+47 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Wcn3988 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8835 Firmware+31 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sm6250 FirmwareQualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 662 Mobile Platform FirmwareQualcomm Snapdragon 7C Compute Platform Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+50 | 6/4/2026 | 17/6/2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm X2000094 FirmwareQualcomm Xg101002 FirmwareQualcomm Xg101032 FirmwareQualcomm Xg101039 Firmware+24 | 6/4/2026 | 17/6/2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. |