Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated… | |
| Analizada | Media (4.3) | 0.28% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource… | |
| Pendiente de análisis | Baja (3.9) | 0.20% | — | LibarchiveAI | 10/7/2026 | 21/9/2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of… | |
| Analizada | Alta (8) | 0.32% | — | Elastic Kibana | 1/7/2026 | 2/7/2026 | Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 1/7/2026 | 2/7/2026 | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable. | |
| Analizada | Media (4.4) | 0.32% | — | Elastic Kibana | 1/7/2026 | 2/7/2026 | Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 1/7/2026 | 2/7/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render Kibana unavailable. | |
| Aplazada | Alta (7.2) | 0.36% | — | DolibarrAI | 30/6/2026 | 14/7/2026 | Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints… | |
| Pendiente de análisis | Alta (7.5) | 0.73% | — | LibarchiveAI | 30/6/2026 | 2/10/2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory… | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Ffmpeg LibavcodecAI | 28/6/2026 | 1/9/2026 | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream… | |
| Analizada | Alta (7.1) | 0.21% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a… | |
| Analizada | Crítica (9.6) | 0.49% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry listed in icons.json validates the icon path, opens it, and streams… | |
| Analizada | Crítica (9.6) | 0.46% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in externalTrigger() allows an attacker to overwrite the internal appId property by… | |
| Modificada | Crítica (9.8) | 0.54% | 💥 PoC | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published a PUBLIC write query, modifies every… | |
| Analizada | Alta (8.2) | 0.41% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT URL minted on the victim's IAM identity. The endpoint also returns… | |
| Analizada | Media (5.3) | 0.29% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table… | |
| Analizada | Alta (7.3) | 0.19% | — | Budibase | 26/6/2026 | 30/6/2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Discord/MS Teams) to an authenticated Budibase user account, with no… | |
| Aplazada | Alta (8.7) | 0.58% | — | LibaisAI | 25/6/2026 | 25/6/2026 | libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds… | |
| Aplazada | Media (6.8) | 0.17% | 💥 PoC | Toshiba Generic IO Memory Access DriverAIDynabook Generic IO Memory Access DriverAI | 25/6/2026 | 25/6/2026 | Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory. | |
| Pendiente de análisis | Alta (7.1) | 0.88% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In… | |
| Pendiente de análisis | Alta (7.1) | 0.58% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately… | |
| Pendiente de análisis | Alta (7.1) | 0.64% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then… | |
| Pendiente de análisis | Alta (7.6) | 0.42% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds… | |
| Pendiente de análisis | Alta (8.8) | 1.0% | 💥 PoC | Ffmpeg LibavcodecAI | 18/6/2026 | 23/7/2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2. |