Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.43%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (7.8)0.43%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (7.8)0.19%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.8)0.43%—Nvidia Nemo Megatron Bridge1/7/20262/7/2026
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (8.2)0.41%—Electron Builder-util-runtimeElectron-builder30/6/202626/8/2026
electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential-bearing headers — most notably…
AnalizadaAlta (7.8)0.19%—Electron-builder30/6/202618/8/2026
electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which…
AplazadaMedia (6.1)0.25%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the…
AplazadaCrítica (9.8)0.47%—Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI30/6/202630/6/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0. NOTE: The vendor was contacted and it was…
AplazadaCrítica (9.3)0.54%—Delta Electronics Dvp12seAI30/6/202630/6/2026
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated interaction with security-sensitive PLC functions.
AplazadaCrítica (9.3)0.43%—Delta Electronics Dvp12seAI30/6/202630/6/2026
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP service.
AnalizadaAlta (8.4)0.44%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and…
AnalizadaCrítica (9.3)0.57%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
AnalizadaCrítica (9.3)0.68%—Daktronics Dmp-5000 FirmwareDaktronics Dmp-8000 FirmwareDaktronics Vfc-dmp-5000 Firmware26/6/20266/7/2026
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
AplazadaCrítica (9.3)0.43%—ElectronAI23/6/202625/6/2026
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API…
Pendiente de análisisMedia (5.1)0.49%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202624/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access…
Pendiente de análisisAlta (8.7)0.72%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202622/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own…
AplazadaMedia (4.8)0.18%—ElectronAIActualbudget ActualAI12/6/202617/6/2026
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the…
AplazadaCrítica (9.8)0.64%💥 PoCDTS Electronics Industry AND Trade LTD Redline Wr3200AI5/6/202623/7/2026
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
Pendiente de análisisBaja (2.2)0.38%—Openstack NeutronAI4/6/202622/7/2026
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network…
Pendiente de análisisBaja (2)0.13%—Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI29/5/20266/10/2026
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS…
AplazadaMedia (5.3)0.43%—Openstack NeutronAI28/5/202621/7/2026
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project…
AplazadaCrítica (9.3)0.41%—Mennekes AmtronAI28/5/202617/6/2026
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.
AplazadaCrítica (9.3)0.73%—Mennekes AmtronAI28/5/202617/6/2026
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.
AplazadaMedia (5.5)0.41%—Itsourcecode Electronic Judging SystemAI26/5/202623/7/2026
A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.45%—Itsourcecode Electronic Judging SystemAI26/5/202623/7/2026
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be…