Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (5.3) | 0.58% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content… | |
| En análisis | Media (5.9) | 0.26% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Electron made the upstream request through defaultSession instead of the session… | |
| En análisis | Media (5.9) | 0.32% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a… | |
| En análisis | Alta (7.4) | 0.35% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page loaded from a remote origin could… | |
| En análisis | Media (6) | 0.14% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file… | |
| En análisis | Media (6.6) | 0.26% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate,… | |
| En análisis | Alta (7.5) | 0.30% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain… | |
| En análisis | Baja (3.1) | 0.22% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or… | |
| En análisis | Media (5.9) | 0.19% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe… | |
| En análisis | Baja (3.9) | 0.14% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process… | |
| En análisis | Media (6.3) | 0.11% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable fuse-based… | |
| Aplazada | Alta (7.1) | 0.43% | — | Openstack NeutronAI | 5/8/2026 | 31/8/2026 | In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim… | |
| Aplazada | Alta (7.1) | 0.27% | — | LG Electronics SmartshareAIMicrosoft Windows 10AI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | |
| Aplazada | Media (4.3) | 0.19% | — | Facturacion Electronica Costa RicaAI | 29/7/2026 | 30/7/2026 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.35% | — | Tarteaucitron.jsAI | 17/7/2026 | 23/7/2026 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whether the cookie corresponds to a service handled by tarteaucitron. If an… | |
| Aplazada | Media (6.2) | 0.16% | — | Pegatron Tdelo64.sysAI | 15/7/2026 | 15/7/2026 | Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted… | |
| Aplazada | Crítica (9.8) | 0.46% | 💥 PoC | Pegatron Tdelo64.sysAI | 15/7/2026 | 16/7/2026 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Electronic Judging SystemAI | 14/7/2026 | 15/7/2026 | A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.php. This manipulation of the argument fname causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.23% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.43% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.43% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.43% | — | Nvidia Nemo Megatron Bridge | 1/7/2026 | 2/7/2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |