Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1654 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 1.1% | — | Mimiclab Mcp-pdf-visionAI | 8/8/2026 | 12/8/2026 | A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem… | |
| Aplazada | Alta (8.8) | 0.17% | — | Lucid Vision Labs Arena SDKAI | 7/8/2026 | 26/8/2026 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency… | |
| Analizada | Crítica (9.9) | 1.0% | — | Microsoft Entra Provisioning Service | 7/8/2026 | 7/8/2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.3) | 0.19% | — | Geovision Gv-asmanagerAI | 4/8/2026 | 9/9/2026 | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed… | |
| Aplazada | Alta (7.2) | 0.92% | — | Hikvision Networking ProductsAI | 31/7/2026 | 28/8/2026 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Umai Vision Traffic Analysis SystemAI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34. | |
| Analizada | Alta (8.8) | 0.43% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 28/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Crítica (9.8) | 0.66% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 29/7/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap… | |
| Modificada | Crítica (9.8) | 0.78% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. | |
| Modificada | Crítica (9.8) | 0.85% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or… | |
| Modificada | Crítica (9.8) | 0.80% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or… | |
| Modificada | Alta (8.1) | 0.57% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2026 | 17/8/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination. | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected… | |
| Modificada | Alta (7.8) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected… | |
| Analizada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 28/7/2026 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Modificada | Alta (8.8) | 0.47% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 27/7/2026 | 17/8/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 29/7/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service. | |
| Analizada | Crítica (9.8) | 0.59% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 28/7/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. | |
| Modificada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos | 27/7/2026 | 17/8/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. | |
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/7/2026 | 17/8/2026 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Crítica (9.8) | 0.56% | — | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 27/7/2026 | 17/8/2026 | An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization. |