Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
930 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.18% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Analizada | Alta (7.3) | 0.29% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Analizada | Alta (7.3) | 0.35% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Aplazada | Alta (8.8) | 0.41% | — | Roche Diagnostics Navify Digital PathologyAIRabbitmqAI | 2/6/2026 | 22/7/2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1. | |
| Analizada | Media (5.6) | 0.18% | — | Broadcom Rabbitmq Server | 27/5/2026 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13. | |
| Analizada | Media (5.3) | 0.20% | — | Broadcom Rabbitmq Server | 27/5/2026 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID.… | |
| Analizada | Crítica (9.9) | 0.58% | — | Vowpalwabbit Vowpal Wabbit | 26/5/2026 | 24/7/2026 | Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_gen_and_load.py. The… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Genetec RabbitmqAI | 26/5/2026 | 24/7/2026 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. | |
| Aplazada | Media (6.9) | 0.25% | — | ABB Rtu500AI | 26/5/2026 | 23/7/2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. | |
| Aplazada | Alta (8.6) | 0.16% | — | AudiograbberAI | 23/5/2026 | 23/7/2026 | Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious input in the Interpret or Album fields that triggers a buffer overflow, overwriting SEH pointers and executing injected… | |
| Aplazada | Alta (8.3) | 1.1% | 💥 Exploit | Amazon MQAIRabbitmq AWSAI | 20/5/2026 | 23/7/2026 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. To… | |
| Modificada | Alta (8.4) | 0.20% | — | Tabby | 15/5/2026 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233. | |
| Analizada | Alta (7.1) | 0.24% | — | Tabby | 15/5/2026 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafted terminal output containing… | |
| Modificada | Alta (7) | 0.18% | — | Tabby | 15/5/2026 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal session output without user interaction, enabling shell command execution when a user displays attacker-controlled content. The ZModemMiddleware… | |
| Analizada | Crítica (9.4) | 0.48% | — | Tabby | 15/5/2026 | 17/6/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or sandboxing. An… | |
| Aplazada | Crítica (9.3) | 1.0% | — | CrabboxAI | 14/5/2026 | 14/7/2026 | Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive… | |
| Aplazada | Alta (8.6) | 0.46% | — | CrabboxAI | 14/5/2026 | 14/7/2026 | Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket,… | |
| Aplazada | Alta (8.7) | 0.69% | — | CrabboxAI | 14/5/2026 | 14/7/2026 | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass… | |
| Aplazada | Media (6.8) | 0.19% | — | CrabboxAI | 11/5/2026 | 14/7/2026 | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory. Attackers can craft a malicious .crabbox.yaml or crabbox.yaml file with traversal sequences to… | |
| Aplazada | Alta (7.7) | 0.69% | — | CrabboxAI | 11/5/2026 | 14/7/2026 | Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a… | |
| Analizada | Alta (7.3) | 0.26% | — | Zabbix | 6/5/2026 | 18/9/2026 | The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from… | |
| Analizada | Media (5.1) | 0.22% | — | Zabbix | 6/5/2026 | 18/9/2026 | A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session. | |
| Analizada | Alta (7.3) | 0.26% | — | Zabbix | 6/5/2026 | 18/9/2026 | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip. | |
| Aplazada | Baja (2.1) | 1.8% | — | Crazyrabbitltc Mcp-code-review-serverAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exploit is now public… | |
| Aplazada | Alta (7.1) | 0.18% | — | ABB Ac800mAIABB Symphony Plus SD SeriesAIABB Symphony Plus MRAIABB S+ OperationsAI+3 | 13/4/2026 | 17/6/2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication interfaces of the PM… |