Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

3320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.45%—ArcadedbAI15/9/202630/9/2026
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without…
AplazadaAlta (8.1)0.50%—ArcadedbAI15/9/202630/9/2026
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and…
AplazadaMedia (5.3)0.21%—Arc53 DocsgptAI14/9/202623/9/2026
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud…
Pendiente de análisisBaja (2.5)0.18%—LibarchiveAILibarchive BsdtarAI13/9/202622/9/2026
libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename…
AplazadaMedia (5.3)0.49%—Kagisearch SmallwebAI13/9/202615/9/2026
A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be…
AplazadaMedia (6.9)0.83%—MogublogAIElasticsearchAI11/9/202611/9/2026
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious…
AplazadaMedia (5.3)0.47%—Tp-link Archer Mr600AITp-link Tl-mr6400AI10/9/202611/9/2026
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful…
AplazadaMedia (4.8)0.73%—Tp-link Archer Mr600AITp-link Tl-mr6400AI10/9/202611/9/2026
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a…
AplazadaAlta (7.5)0.39%—WP Fast Total SearchAI10/9/202610/9/2026
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
Pendiente de análisisAlta (8.8)0.82%—Microsoft Azure ARCAI8/9/202610/9/2026
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.7)0.13%—ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI8/9/202610/9/2026
A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to cause a denial of service or disclose sensitive information. This…
Pendiente de análisisAlta (7.8)0.16%—ARM Bifrost GPU Userspace DriverAIARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue…
Pendiente de análisisAlta (7.8)0.16%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisAlta (7.8)0.16%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisAlta (7.8)0.16%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU processing operations to access already freed memory. This issue affects Valhall GPU Kernel Driver: from r50p0 through r54p3, r55p0; Arm…
Pendiente de análisisMedia (5.1)0.11%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisMedia (4)0.11%—ARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAIARM 5TH GEN GPU Architecture Kernel DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
Pendiente de análisisMedia (5.1)0.11%—ARM Valhall GPU Userspace DriverAIARM 5TH GEN GPU Architecture Userspace DriverAI8/9/202610/9/2026
Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Valhall GPU Userspace Driver:…
Pendiente de análisisAlta (7.5)0.24%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/202610/9/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue…
Pendiente de análisisMedia (4.4)0.17%—ARM LTD ARM 5TH GEN GPU Architecture Kernel DriverAIARM Bifrost GPU Kernel DriverAIARM Valhall GPU Kernel DriverAI8/9/20268/9/2026
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel…
AplazadaBaja (2.1)0.37%—Starcounter-jack Json-patchAI8/9/202628/9/2026
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation…
AplazadaMedia (5.5)0.76%—Starcounter-jack Json-patchAI7/9/20268/9/2026
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The…
AplazadaAlta (7.1)0.43%—ArcaneAI5/9/202623/9/2026
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with…
AplazadaMedia (5.4)0.20%—Search Atlas SEOAI5/9/20268/9/2026
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.