Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.19% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Media (5.5) | 0.16% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Mz-automation Lib60870-cAI | 6/8/2026 | 31/8/2026 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding… | |
| Aplazada | Alta (7.2) | 0.34% | — | Karr Security SystemAISwds Dealer Installed Automotive Anti Theft SystemAI | 5/8/2026 | 8/9/2026 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions,… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Business Automation Insights | 5/8/2026 | 10/8/2026 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | |
| Analizada | Baja (3.8) | 0.17% | — | IBM Business Automation Workflow | 5/8/2026 | 10/8/2026 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing… | |
| Aplazada | Alta (7.5) | 2.0% | 💥 Exploit | Aiwu AI Chatbot Workflow AutomationAI | 5/8/2026 | 12/8/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The… | |
| Analizada | Alta (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analizada | Crítica (9.6) | 0.19% | — | Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+197 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Media (5.5) | 0.86% | — | Mz-automation Libiec61850AI | 3/8/2026 | 12/8/2026 | A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. This manipulation causes out-of-bounds read. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.86% | — | Mz-automation Libiec61850AI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component Report Sending Path Handler. The manipulation results in free of memory not on the heap. It is… | |
| Aplazada | Media (6.5) | 0.30% | — | Automattic Woocommerce PaymentsAI | 1/8/2026 | 26/8/2026 | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Mz-automation Libiec61850AI | 31/7/2026 | 3/9/2026 | An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame. | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Redhat Ansible Automation PlatformAIRedhat AAP GatewayAI | 31/7/2026 | 4/8/2026 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The… | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |
| Aplazada | Alta (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. | |
| Aplazada | Alta (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. | |
| Aplazada | Alta (7.3) | 0.20% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. |