Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.39% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23. | |
| Analizada | Baja (3.7) | 0.34% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7,… | |
| Analizada | Media (5.3) | 0.41% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23. | |
| Analizada | Crítica (9.1) | 0.91% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23. | |
| Analizada | Alta (7.2) | 0.51% | — | Hashicorp Vault | 1/8/2025 | 17/6/2026 | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22. | |
| Aplazada | Media (6.9) | 0.46% | — | CommvaultAI | 25/7/2025 | 17/6/2026 | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault… | |
| Aplazada | Alta (8.5) | 0.18% | — | CommvaultAI | 25/7/2025 | 17/6/2026 | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability… | |
| Aplazada | Alta (8.5) | 0.12% | — | CommvaultAI | 25/7/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compromise any assigned Windows access nodes. This may allow unauthorized… | |
| Modificada | Alta (7.8) | 0.18% | — | Autodesk Infrastructure Parts EditorAutodesk InventorAutodesk Navisworks ManageAutodesk Navisworks Simulate+2 | 24/7/2025 | 17/6/2026 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vaultdweller LeykaAI | 4/7/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects Leyka: from n/a through <= 3.32.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Vaultdweller LeykaAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows DOM-Based XSS.This issue affects Leyka: from n/a through <= 3.32.1. | |
| Analizada | Baja (3.1) | 0.27% | — | Hashicorp Vault | 25/6/2025 | 17/6/2026 | Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22. | |
| Aplazada | Alta (8.8) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. | |
| Aplazada | Alta (8.1) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault… | |
| Aplazada | Alta (8.8) | 2.1% | — | Dell Controlvault3AIDell Controlvault 3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.8) | 3.4% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.4) | 1.9% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability. | |
| Aplazada | Crítica (9.9) | 0.77% | — | Wildermyth WilderforgeAIWildermyth ExamplemodAIWildermyth WilderworkspaceAIWildermythgameproviderAI+5 | 9/6/2025 | 17/6/2026 | WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions… | |
| Analizada | Alta (8.8) | 0.44% | — | Hashicorp Vault | 2/5/2025 | 17/6/2026 | Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypass of the bound_locations parameter on login. Fixed in Vault Community Edition 1.19.1 and Vault Enterprise 1.19.1, 1.18.7, 1.17.14, 1.16.18. | |
| Analizada | Media (6.5) | 0.45% | — | Hashicorp VaultOpenbao | 2/5/2025 | 17/6/2026 | Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault… | |
| Analizada | Alta (8.7) | 2.3% | ⚠ Explotación activa | Commvault | 25/4/2025 | 17/6/2026 | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux… | |
| Analizada | Crítica (9.3) | 98% | ⚠ Explotación activa💥 Exploit | Commvault | 22/4/2025 | 17/6/2026 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center… | |
| Modificada | Alta (7.8) | 0.29% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+13 | 15/4/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Aplazada | Media (6) | 0.17% | — | Arctera Enterprise Vault Collection ModuleAIVeritas Ediscovery PlatformAI | 15/4/2025 | 17/6/2026 | Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher. | |
| Aplazada | Media (5.3) | 0.31% | — | Vmware Cloud ConfigAIVmware VaultAI | 10/4/2025 | 17/6/2026 | In this case the SessionManager persists the first token it retrieves and will continue to use that token even if client requests to the Spring Cloud Config Server include a X-CONFIG-TOKEN header with a different value. Affected Spring Products and Versions Spring Cloud Config: * 2.2.1.RELEASE - 4.2.1 Mitigation Users… |