Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.68% | — | Hgiga OakloudsAI | 18/9/2026 | 18/9/2026 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files. | |
| Aplazada | Crítica (9.3) | 0.91% | — | Hgiga OakloudsAI | 18/9/2026 | 18/9/2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | |
| Aplazada | Media (5.5) | 0.70% | — | O-ran-sc SMO OAMAIO-ran-sc VES CollectorAI | 17/9/2026 | 18/9/2026 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem… | |
| Aplazada | Baja (2.1) | 0.52% | — | O-ran-sc SMO OAMAIO-ran-sc VES CollectorAI | 17/9/2026 | 22/9/2026 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project… | |
| Aplazada | Baja (2.1) | 0.52% | — | O-ran-sc SMO OAMAIO-ran-sc VES CollectorAI | 17/9/2026 | 18/9/2026 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was… | |
| Aplazada | Baja (2.1) | 0.53% | — | O-ran-sc SMO OAMAIO-ran-sc VES CollectorAI | 17/9/2026 | 23/9/2026 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Pendiente de análisis | Alta (7.4) | 0.40% | — | KeycloakAI | 17/9/2026 | 22/9/2026 | A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such… | |
| Aplazada | Alta (8.1) | 0.91% | — | Paid DownloadsAI | 17/9/2026 | 19/9/2026 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin()… | |
| Aplazada | Crítica (9.8) | 1.1% | 💥 PoC | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Alta (8.6) | 0.45% | — | GoadminAI | 16/9/2026 | 22/9/2026 | GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform… | |
| Pendiente de análisis | Media (6.5) | 0.56% | — | Cisco Broadworks Commpilot Application SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this… | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.28% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.9) | 0.34% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Crítica (9.9) | 0.27% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Keycloak-servicesAI | 16/9/2026 | 16/9/2026 | A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in… | |
| Pendiente de análisis | Alta (7.2) | 0.45% | — | KeycloakAI | 16/9/2026 | 16/9/2026 | Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles. | |
| Pendiente de análisis | Alta (7.5) | 0.81% | — | Keycloak ServicesAI | 16/9/2026 | 16/9/2026 | A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent… | |
| Pendiente de análisis | Alta (7.5) | 0.52% | — | KeycloakAI | 16/9/2026 | 16/9/2026 | A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending… | |
| Pendiente de análisis | Alta (8.1) | 0.85% | — | KeycloakAI | 16/9/2026 | 18/9/2026 | Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments.… | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Jenkins Keycloak Authentication PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that… | |
| Analizada | Crítica (9.1) | 0.81% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same… |