Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
8415 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.24% | — | Cisco CjoseAI | 9/9/2026 | 10/9/2026 | OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates… | |
| Pendiente de análisis | Alta (7.1) | 0.16% | — | Cisco UCS ServersAICisco UCS AppliancesAI | 8/9/2026 | 11/9/2026 | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected… | |
| Pendiente de análisis | Alta (7.4) | 0.94% | — | Microsoft Discovery StudioAI | 3/9/2026 | 8/9/2026 | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | Cisco Secure EmailAI | 2/9/2026 | 2/9/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | Cisco Secure EmailAI | 2/9/2026 | 2/9/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+1 | 2/9/2026 | 2/9/2026 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Analizada | Crítica (9.8) | 0.73% | — | Cisco IOS XR | 2/9/2026 | 17/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.8) | 0.72% | 💥 PoC | Cisco Nexus 9000AI | 2/9/2026 | 3/9/2026 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A… | |
| Analizada | Alta (8.8) | 0.29% | — | Cisco IOS XR | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.8) | 0.30% | — | Cisco IOS XRAI | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | Cisco IOS XRAI | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.2) | 0.23% | — | Cisco IOS XRAI | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Analizada | Alta (8.6) | 0.27% | — | Cisco IOS XR | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | Cisco IOS XRAI | 2/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Aplazada | Crítica (9.8) | 0.61% | — | DisconfAI | 26/8/2026 | 9/9/2026 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Openrisc Or1200AI | 26/8/2026 | 9/9/2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. | |
| Aplazada | Alta (7.5) | 0.26% | — | Openrisc Or1200AI | 26/8/2026 | 9/9/2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS). | |
| Aplazada | Media (6.9) | 0.48% | — | AutomatischAI | 26/8/2026 | 23/9/2026 | Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address with no account raises an error that the… | |
| Aplazada | Alta (8.2) | 0.20% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity… | |
| Aplazada | Media (4.1) | 0.16% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of… | |
| Analizada | Media (5.3) | 0.39% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and… | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Webex APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled… |