Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.15% | — | Nilfs UtilitiesAI | 18/6/2026 | 14/7/2026 | NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Cifs-utilsAI | 18/6/2026 | 31/8/2026 | A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into… | |
| Aplazada | Alta (8.1) | 0.46% | — | Fs-code BookneticAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. | |
| Analizada | Crítica (9.1) | 0.66% | — | I18next-fs-backend | 15/6/2026 | 17/6/2026 | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator… | |
| Aplazada | Alta (7.1) | 0.35% | — | LibnfsAI | 10/6/2026 | 19/7/2026 | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. | |
| Aplazada | Media (5.5) | 0.41% | — | Perfree Go-fastdfs-webAI | 6/6/2026 | 23/7/2026 | A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been published and may be… | |
| Aplazada | Alta (8.6) | 0.15% | — | Labf NfsaxeAI | 4/6/2026 | 22/7/2026 | LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary… | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Aplazada | Crítica (9.3) | 0.35% | — | RustfsAI | 29/5/2026 | 21/7/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts… | |
| Aplazada | Media (6.9) | 0.54% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console listener and returns JSON containing license information such as the… | |
| Aplazada | Media (6) | 0.15% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and also sets Access-Control-Allow-Credentials: true and… | |
| Aplazada | Alta (8.8) | 0.54% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the… | |
| Aplazada | Alta (7.1) | 0.35% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources. The implementation validates GetObject permission on the source… | |
| Aplazada | Alta (8.7) | 0.41% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" license tokens. Because the key is embedded in every published source… | |
| Aplazada | Media (5.3) | 0.24% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), SecretAccessKey, and full JWT claims are printed in plaintext to the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | RustfsAI | 28/5/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in crates/ecstore/src/rpc/http_auth.rs, falls back to the public,… | |
| Pendiente de análisis | Alta (8.4) | 4.0% | — | Zohocorp Manageengine Adselfservice PlusAIZohocorp Manageengine Datasecurity PlusAIZohocorp Manageengine Recoverymanager PlusAI | 21/5/2026 | 23/7/2026 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. | |
| Aplazada | Baja (1.8) | 0.20% | — | Npitre Cramfs-toolsAI | 18/5/2026 | 17/6/2026 | A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack requires a local approach. The exploit is now public and may be used. The patch is named… | |
| Analizada | Alta (7.8) | 0.21% | — | Gitoxidelabs Gix-fs | 13/5/2026 | 17/6/2026 | gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symlink index entries are deferred and… | |
| Aplazada | Baja (1.9) | 0.17% | — | Npitre Cramfs-toolsAI | 11/5/2026 | 17/6/2026 | A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of the file cramfsck.c of the component Directory Handler. Such manipulation leads to path traversal. The attack can only be performed from a local environment. The exploit has been disclosed publicly and… | |
| Aplazada | Alta (8.2) | 0.43% | — | I18next-fs-backendAI | 8/5/2026 | 17/6/2026 | i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath / addPath templates and then read / write the resulting file from disk. The… | |
| Analizada | Baja (3.3) | 0.13% | — | Dell Powerscale Onefs | 8/5/2026 | 17/6/2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Crítica (9.9) | 0.68% | — | Pfsense | 8/5/2026 | 17/6/2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code. |