Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

11.347 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.1)0.38%—IBM Common Licensing AgentAIIBM ARTAI10/9/202611/9/2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
AplazadaAlta (7.3)0.40%—Wensolutions WP TravelAI10/9/202621/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.
Pendiente de análisisMedia (6.8)0.27%—Bosch Sensortec Coines SDKAI10/9/202610/9/2026
An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}}…
Pendiente de análisisAlta (8)0.31%—Boschsensortec Coines SDKAI10/9/202610/9/2026
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided…
Pendiente de análisisMedia (4.3)0.21%—Bosch Bme690 SensorapiAI10/9/202610/9/2026
An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping…
Pendiente de análisisAlta (8.4)0.19%—Bosch Sensortec Bhi385 SensorapiAI10/9/202610/9/2026
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event…
Pendiente de análisisAlta (7.6)0.25%—Bosch Sensortec Bhi360 SensorapiAI10/9/202610/9/2026
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875).…
AplazadaAlta (7.7)0.21%—Redhat OpenshiftAIOpenai OperatorAI9/9/20269/9/2026
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,…
AplazadaMedia (6.8)0.43%—Sina ExtensionAI9/9/20269/9/2026
The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (5.3)0.22%—Wensolutions WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking.
AplazadaBaja (3.7)0.19%—Wensolutions WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state…
Pendiente de análisisCrítica (9)0.47%—Opnsense CoreAI8/9/202625/9/2026
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS…
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
AnalizadaAlta (7.8)0.47%—Microsoft Heif Image Extension8/9/202617/9/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)0.48%—Microsoft WEB Media Extensions8/9/202630/9/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Webp Image Extension8/9/202629/9/2026
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft RAW Image Extension8/9/202622/9/2026
Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.47%—Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer8/9/20261/10/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.47%—Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer8/9/20261/10/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
AplazadaAlta (7)0.25%—Watchguard DimensionAI8/9/20268/9/2026
A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
Pendiente de análisisCrítica (9.9)0.39%—Hawtio-operatorAIRedhat OpenshiftAI8/9/20268/9/2026
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole…
AplazadaAlta (8.5)0.38%—Siemens TeamcenterAI8/9/20269/9/2026
A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute…
AplazadaAlta (8.6)0.19%—Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI8/9/202614/9/2026
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All…
AplazadaBaja (2.1)0.47%—Sourcecodester Simple Traffic Offense SystemAI7/9/202611/9/2026
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of…
AplazadaMedia (5.5)0.76%—Sourcecodester Simple Traffic Offense SystemAI7/9/20268/9/2026
A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The…