Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
293.960 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.23% | — | Pulpproject Pulp AnsibleAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Pulp ContainerAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token… | |
| Aplazada | Alta (7.2) | 0.37% | — | KirkiAI | 7/10/2026 | 7/10/2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value… | |
| Pendiente de análisis | Crítica (9.3) | 0.37% | — | Flexnet PublisherAI | 7/10/2026 | 7/10/2026 | A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials. | |
| Aplazada | Crítica (9.3) | 0.32% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router… | |
| Aplazada | Alta (7.7) | 0.13% | — | Asus Rt-be57AI | 7/10/2026 | 7/10/2026 | A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the '… | |
| Aplazada | Crítica (9.3) | 0.19% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (8.4) | 0.21% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for… | |
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Candlepinproject CandlepinAI | 7/10/2026 | 7/10/2026 | A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization… | |
| Aplazada | Crítica (9.2) | 0.65% | — | Asustor ADMAI | 7/10/2026 | 7/10/2026 | An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to… | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Octopus ServerAI | 7/10/2026 | 7/10/2026 | In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to… | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | Nvidia Model OptimizerAI | 6/10/2026 | 7/10/2026 | NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | |
| Pendiente de análisis | Media (5.5) | 0.12% | — | Nvidia TensorrtAI | 6/10/2026 | 7/10/2026 | NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service. | |
| Pendiente de análisis | Media (5.3) | 0.22% | — | Backstage Plugin-scaffolder-backendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Backstage Plugin-scaffolder-backendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in… | |
| Pendiente de análisis | Alta (8.1) | 0.36% | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Backstage Plugin-scaffolder-backendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used… | |
| Pendiente de análisis | Crítica (9.6) | 0.47% | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution… | |
| Pendiente de análisis | Alta (8.5) | 0.33% | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific… | |
| Pendiente de análisis | Media (4.9) | 0.27% | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder… | |
| Pendiente de análisis | Alta (7.7) | 0.46% | — | AMD Rocm Communication Collectives LibraryAI | 6/10/2026 | 7/10/2026 | Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution. | |
| Pendiente de análisis | Media (6.8) | 0.12% | — | Hdfgroup Hdf5AI | 6/10/2026 | 7/10/2026 | A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets an attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the… | |
| Pendiente de análisis | Alta (8.5) | 0.16% | — | Hdfgroup Hdf5AI | 6/10/2026 | 7/10/2026 | A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace… | |
| Pendiente de análisis | Media (6.4) | 0.27% | — | Backstage Plugin Proxy BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the… | |
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Backstage Plugin-auth-backend-module-oidc-providerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may… |