Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 25 respecto a la semana anterior
Críticas / altas1269▼ 244 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

11.345 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9)6.9%—Cisco IOS XRCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE+125/9/202511/8/2026
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or…
AnalizadaAlta (8.6)87%⚠ Explotación activa💥 ExploitCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense25/9/202511/8/2026
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS)…
AnalizadaCrítica (9.9)71%⚠ Explotación activa💥 PoCCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense25/9/202511/8/2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of…
AplazadaCrítica (9.9)0.52%—Gardener Extensions AWSAIGardener Extensions AzureAIGardener Extensions OpenstackAIGardener Extensions GCPAI+125/9/202517/6/2026
Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.0, OpenStack providers prior to version 1.49.0, and GCP providers prior to…
AplazadaCrítica (9.6)0.56%💥 PoCNPMAISiemens NXAI24/9/202517/6/2026
Se insertó código malicioso en el paquete Nx (sistema de compilación) y varios plugins relacionados. El paquete manipulado se publicó en el registro de software npm, a través de un ataque a la cadena de suministro. Las versiones afectadas contienen código que escanea el sistema de archivos, recopila credenciales y las…
AnalizadaCrítica (9.8)5.4%⚠ Explotación activa💥 PoCGoogle ChromeSiemens Cadra24/9/202514/7/2026
Confusión de tipos en V8 en Google Chrome anterior a 140.0.7339.185 permitió a un atacante remoto potencialmente explotar la corrupción de la pila a través de una página HTML manipulada. (Gravedad de seguridad de Chromium: Alta)
AplazadaAlta (8.6)0.87%💥 PoCOpenai Codex CLIAIOpenai Codex IDE ExtensionAI22/9/202517/6/2026
Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the…
AplazadaMedia (6.5)0.20%—Agency Dominion INC Fusion Page Builder Extension GalleryAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery fusion-extension-gallery allows Stored XSS.This issue affects Fusion Page Builder : Extension – Gallery: from n/a through <= 1.7.6.
AplazadaMedia (6.5)0.20%—Stonehenge Creations Events Manager OpenstreetmapsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stonehenge Creations Events Manager – OpenStreetMaps stonehenge-em-osm allows Stored XSS.This issue affects Events Manager – OpenStreetMaps: from n/a through <= 4.2.1.
AplazadaMedia (5.9)0.30%—Sureshkumarmukhiya Append Extensions ON PagesAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Kumar Mukhiya Append extensions on Pages append-extensions-on-pages allows Stored XSS.This issue affects Append extensions on Pages: from n/a through <= 1.1.2.
AplazadaAlta (8.8)0.59%—Cyrisma SensorAI16/9/202517/6/2026
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM by replacing DataSpotliteAgent.exe or any other binaries called by the Cyrisma_Agent…
AnalizadaAlta (7.8)0.29%—Getgreenshot Greenshot16/9/202517/6/2026
Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled data received in a WM_COPYDATA message using BinaryFormatter.Deserialize without prior validation or authentication, allowing a local process at the same integrity level to trigger arbitrary code…
AnalizadaCrítica (9.8)7.3%—Opensynergy Blue SDK12/9/202517/6/2026
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote…
AnalizadaMedia (6.5)0.56%—Opensynergy Blue SDK12/9/202517/6/2026
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security validation and make the…
AnalizadaAlta (7.5)0.74%—Opensynergy Blue SDK12/9/202517/6/2026
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain sensitive information.
AnalizadaMedia (5.3)5.6%—Opensynergy Blue SDK12/9/202517/6/2026
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null identifier assigned as…
AnalizadaAlta (7.3)0.29%—HP Poly Lens Desktop9/9/202517/6/2026
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted.
AnalizadaMedia (5.1)3.9%—Pfsense9/9/202514/7/2026
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package"…
AnalizadaMedia (5.1)0.88%—Pfsense9/9/202514/7/2026
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package"…
AnalizadaMedia (5.3)16%—Pfsense9/9/202514/7/2026
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which…
AplazadaMedia (6.8)0.46%—Crestron Touchscreens X70AI9/9/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061…
AnalizadaMedia (5.1)16%—Pfsense9/9/202514/7/2026
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.
AnalizadaMedia (5.1)10%—Pfsense9/9/202517/6/2026
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the…
AnalizadaMedia (5.3)0.92%—Pfsense9/9/202514/7/2026
In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker…
AnalizadaMedia (4.8)1.1%—Pfsense9/9/202514/7/2026
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.