Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
9810 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.37% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages. | |
| Pendiente de análisis | Alta (7.5) | 0.27% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 19/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation. | |
| Pendiente de análisis | Alta (7.5) | 0.68% | — | Datadog PHP TracerAI | 17/9/2026 | 23/9/2026 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES. A remote… | |
| Aplazada | Alta (8.7) | 0.64% | — | MispAICakephpAI | 17/9/2026 | 22/9/2026 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working,… | |
| Aplazada | Media (5.4) | 0.14% | — | Publishpress SeriesAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | |
| Pendiente de análisis | Crítica (9.2) | 0.62% | 💥 PoC | CakephpAI | 17/9/2026 | 30/9/2026 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate… | |
| Aplazada | Alta (7.6) | 0.38% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (5.1) | 0.39% | — | Misp SachertortephpAI | 17/9/2026 | 18/9/2026 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0. Because… | |
| Aplazada | Alta (7.2) | 0.26% | — | PhplistAI | 16/9/2026 | 22/9/2026 | phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification. | |
| Pendiente de análisis | Alta (8.7) | 0.60% | — | OpennhpAI | 16/9/2026 | 22/9/2026 | OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure… | |
| Pendiente de análisis | Alta (8.8) | 0.78% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Pendiente de análisis | Crítica (9.3) | 0.70% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Pendiente de análisis | Crítica (9.3) | 0.70% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Analizada | Crítica (9.3) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.6) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Crítica (9.3) | 1.1% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.97% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.4) | 0.79% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.97% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (6.8) | 0.72% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Media (5.1) | 0.98% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (8.6) | 1.0% | — | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Analizada | Alta (7) | 1.0% | 💥 PoC | HP Linux Imaging AND Printing | 16/9/2026 | 21/9/2026 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. | |
| Pendiente de análisis | Alta (7.5) | 0.66% | — | Reactphp HttpAI | 16/9/2026 | 30/9/2026 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete… |