Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
8450 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.35% | — | Openrisc Or1200AI | 26/8/2026 | 9/9/2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. | |
| Aplazada | Alta (7.5) | 0.26% | — | Openrisc Or1200AI | 26/8/2026 | 9/9/2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS). | |
| Aplazada | Media (6.9) | 0.48% | — | AutomatischAI | 26/8/2026 | 23/9/2026 | Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address with no account raises an error that the… | |
| Aplazada | Alta (8.2) | 0.20% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity… | |
| Aplazada | Media (4.1) | 0.16% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of… | |
| Analizada | Media (5.3) | 0.39% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and… | |
| Analizada | Alta (8.8) | 0.42% | — | Cisco Talos Intelligence FOR Enterprise Security Cloud | 19/8/2026 | 21/8/2026 | In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Webex APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled… | |
| Pendiente de análisis | Crítica (10) | 0.48% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Crítica (10) | 0.61% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Cisco Unified Intelligence CenterAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Cisco BroadworksAI | 19/8/2026 | 20/8/2026 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.6) | 0.44% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (10) | 0.56% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (10) | 0.49% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | Cisco RoomosAI | 19/8/2026 | 20/8/2026 | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB… | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input… | |
| Pendiente de análisis | Crítica (9.9) | 0.53% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding… | |
| Pendiente de análisis | Crítica (10) | 0.55% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Aplazada | Media (4.3) | 0.38% | — | DiscourseAI | 17/8/2026 | 18/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing category moderator was not a participant in… |