Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.81% | 💥 PoC | Aimy-extensions Aimy Captcha-less Form Guard | 29/7/2026 | 5/8/2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | |
| Aplazada | Alta (8.4) | 0.51% | — | Pulumi CrossguardAI | 24/7/2026 | 28/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary… | |
| Aplazada | Alta (8.3) | 0.54% | — | Pulumi Crossguard Policy PacksAI | 24/7/2026 | 30/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0. | |
| Aplazada | Crítica (9) | 0.41% | — | Wireguard EasyAI | 16/7/2026 | 18/7/2026 | WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed… | |
| Analizada | Media (6.3) | 0.14% | — | Adguardhome | 15/7/2026 | 30/7/2026 | AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for… | |
| Pendiente de análisis | Crítica (9.3) | 0.43% | — | Guardrails-detectorsAI | 10/7/2026 | 31/8/2026 | A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.53% | — | Guardrails-detectorsAI | 10/7/2026 | 30/9/2026 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from… | |
| Aplazada | Media (5.8) | 0.14% | — | Samsung KnoxguardmanagerAI | 10/7/2026 | 10/7/2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. | |
| Pendiente de análisis | Alta (8.3) | 0.20% | — | Tenable Nessus Remote CollectorAITenable GuardianAITenable CMCAI | 9/7/2026 | 9/7/2026 | When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and… | |
| Modificada | Alta (8.7) | 0.51% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly… | |
| Modificada | Media (6.9) | 0.44% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys. | |
| Modificada | Media (5.3) | 0.31% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate… | |
| Modificada | Media (4.8) | 0.25% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… | |
| Analizada | Alta (7.7) | 0.38% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. | |
| Modificada | Media (5.9) | 0.23% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster. | |
| Analizada | Alta (8.6) | 0.33% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image. | |
| Modificada | Alta (8.6) | 0.72% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. | |
| Modificada | Alta (8.6) | 0.72% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI. | |
| Modificada | Media (4.8) | 0.27% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947. | |
| Modificada | Media (4.8) | 0.27% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up… | |
| Modificada | Media (4.8) | 0.27% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and… | |
| Modificada | Media (4.8) | 0.27% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. | |
| Modificada | Media (4.8) | 0.27% | — | Watchguard Fireware | 3/7/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. |