Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

4639 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.42%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,…
AnalizadaAlta (7.5)0.23%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized…
AnalizadaAlta (8.2)0.46%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.…
AnalizadaMedia (4.4)0.33%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to…
AnalizadaMedia (6.5)0.31%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle…
AnalizadaMedia (5.4)0.29%—Redhat Openshift Update ServiceRedhat Quay14/8/202620/8/2026
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from…
AplazadaCrítica (9.8)0.96%—Doobidoo Mcp-memory-serviceAI14/8/202616/9/2026
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload…
AplazadaAlta (8.8)0.42%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
AplazadaMedia (6.5)0.37%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
AnalizadaAlta (7.5)0.34%—Apple Servicetalk12/8/20263/9/2026
ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.
Pendiente de análisisCrítica (9.4)1.8%—GMS Dispatcher ServiceAI11/8/202628/8/2026
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
AnalizadaCrítica (9.4)0.83%—Microsoft Azure Kubernetes Service11/8/202612/8/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisMedia (6.3)0.29%—SAP Netweaver Application Server JavaAIAdobe Document ServiceAI11/8/202626/8/2026
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though…
Pendiente de análisisBaja (3.7)0.19%—SAP Data Services Management ConsoleAI11/8/202626/8/2026
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within…
Pendiente de análisisCrítica (9.9)0.69%—Kuadrant AuthpolicyAIKubernetes ServiceaccountAI10/8/202627/8/2026
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized…
Pendiente de análisisAlta (8)0.42%—Trustyai ServiceAI10/8/202621/9/2026
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the…
Pendiente de análisisAlta (8.1)0.60%—Trustyai-service-operatorAI10/8/202621/9/2026
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code…
Pendiente de análisisMedia (4)0.27%—Adobe Genuine Software Integrity ServiceAI7/8/202617/8/2026
Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require…
AplazadaAlta (7.1)0.16%—Deepcool DisplayserviceAI7/8/202612/8/2026
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now…
AnalizadaCrítica (9.9)1.0%—Microsoft Entra Provisioning Service7/8/20267/8/2026
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)1.7%—Microsoft Azure Service BUS7/8/20267/8/2026
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
AplazadaMedia (6.3)0.22%—Insta InstinaknxserviceappAI6/8/202612/8/2026
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of…
Pendiente de análisisAlta (8.5)0.31%—Foxit PDF Services APIAI6/8/202626/8/2026
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.
Pendiente de análisisMedia (5)0.35%—Cisco Terminal Service AgentAI5/8/20266/8/2026
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least…
Pendiente de análisisCrítica (9.5)0.32%💥 PoCVeeam Service Provider ConsoleAI4/8/20263/9/2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.