Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.50% | — | Pimcore Admin Classic BundleAI | 12/8/2026 | 16/9/2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL… | |
| Pendiente de análisis | Alta (7.7) | 0.97% | — | Nagios XIAINagios CoreAI | 12/8/2026 | 8/9/2026 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position,… | |
| Pendiente de análisis | Alta (7.7) | 0.97% | — | Nagios XIAINagios CoreAI | 12/8/2026 | 8/9/2026 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an… | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | Nagios XIAINagios CoreAI | 12/8/2026 | 8/9/2026 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Nagios CoreAINagios XIAI | 12/8/2026 | 8/9/2026 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Nagios CoreAINagios XIAI | 12/8/2026 | 8/9/2026 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary JavaScript in the victim's browser. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pimcore Admin-ui-classic-bundleAI | 11/8/2026 | 3/9/2026 | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | ClaircoreAI | 11/8/2026 | 14/8/2026 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service. | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | SssdAIRedhat Insights-coreAIClusterlabs PacemakerAI | 11/8/2026 | 14/8/2026 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com. | |
| Pendiente de análisis | Media (6.5) | 0.52% | — | Wildfly CoreAI | 11/8/2026 | 14/8/2026 | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This… | |
| Pendiente de análisis | Media (4.9) | 0.60% | — | Wildfly-coreAI | 11/8/2026 | 14/8/2026 | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file.… | |
| Aplazada | Media (6.1) | 0.32% | — | Corebunch InstaticAI | 10/8/2026 | 28/8/2026 | A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. | |
| Aplazada | Media (5.3) | 0.35% | — | 3coresec TrapdoorAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure. | |
| Aplazada | Baja (1.9) | 0.17% | — | Astralisone Rive-mcp-server-coreAI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The… | |
| Aplazada | Media (5.9) | 0.31% | — | Supertokens CoreAI | 7/8/2026 | 9/9/2026 | A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant. | |
| Pendiente de análisis | Media (4.4) | 0.11% | — | PolicycoreutilsAI | 7/8/2026 | 1/9/2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race… | |
| Aplazada | Alta (7.1) | 0.39% | — | Diboot-coreAI | 6/8/2026 | 24/9/2026 | diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. The only guard, relatedDataSecurityCheck(), returns true unconditionally, so any authenticated user (including a… | |
| Pendiente de análisis | Crítica (9.1) | 0.50% | — | Nasa Core Flight SystemAI | 4/8/2026 | 31/8/2026 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. | |
| Pendiente de análisis | Alta (8.7) | 0.46% | — | Fasterxml Jackson-coreAI | 4/8/2026 | 8/9/2026 | The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the… | |
| Aplazada | Alta (7.1) | 0.29% | — | Coreweave MarimoAI | 4/8/2026 | 16/9/2026 | marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient… | |
| Aplazada | Baja (2.1) | 0.32% | — | Chetans9 Core-php-admin-panelAI | 4/8/2026 | 12/8/2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack… | |
| Pendiente de análisis | Media (6.9) | 0.41% | — | Fasterxml Jackson-coreAI | 4/8/2026 | 8/9/2026 | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive… | |
| Analizada | Media (6.1) | 0.13% | — | Google A2ui/web Core | 4/8/2026 | 23/9/2026 | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in… | |
| Pendiente de análisis | Media (4.4) | 1.1% | — | Wildfly CoreAI | 4/8/2026 | 6/8/2026 | — | |
| Pendiente de análisis | Baja (1.8) | 0.11% | — | Caliptra Core ROMAITaphome Core FirmwareAI | 4/8/2026 | 3/9/2026 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different… |