Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
293.967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.4) | 0.27% | — | Backstage Plugin Proxy BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the… | |
| En análisis | Alta (8.1) | 0.28% | — | Backstage Plugin-auth-backend-module-oidc-providerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may… | |
| Pendiente de análisis | Baja (3.5) | 0.22% | — | Backstage Plugin Kubernetes BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or… | |
| Pendiente de análisis | Alta (8.5) | 0.33% | — | Backstage Plugin Scaffolder Backend Module Bitbucket CloudAIBackstage Plugin Scaffolder Backend Module Bitbucket ServerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a… | |
| Pendiente de análisis | Alta (8.5) | 0.21% | — | Backstage Plugin Scaffolder Backend Module SentryAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Backstage Plugin Catalog Backend Module Bitbucket ServerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server… | |
| Pendiente de análisis | Media (6.8) | 0.28% | — | Backstage Plugin-auth-backend-module-cloudflare-access-providerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature… | |
| En análisis | Media (4.8) | 0.24% | — | Backstage Plugin-proxy-backendAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent… | |
| Pendiente de análisis | Media (5.7) | 0.23% | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 7/10/2026 | Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests… | |
| Pendiente de análisis | Alta (8.8) | 0.28% | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 7/10/2026 | Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated… | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | GhostscriptAI | 6/10/2026 | 7/10/2026 | A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information. | |
| Pendiente de análisis | Media (6.3) | 0.18% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a… | |
| Pendiente de análisis | Media (6.5) | 0.61% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint. | |
| Pendiente de análisis | Media (6.7) | 0.09% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met. Successful exploitation could allow a local attacker to execute arbitrary code with… | |
| Pendiente de análisis | Media (6.7) | 0.09% | — | Aruba Clearpass ClientAI | 6/10/2026 | 7/10/2026 | A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met. | |
| Pendiente de análisis | Media (6.1) | 0.09% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service. | |
| Pendiente de análisis | Alta (7.2) | 0.30% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands. | |
| Pendiente de análisis | Alta (7.2) | 0.52% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating… | |
| Pendiente de análisis | Alta (7.3) | 0.24% | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role. | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service. | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system. | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Aruba Clearpass Policy Manager OnguardAI | 6/10/2026 | 7/10/2026 | A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client. |