Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.55% | — | Redhat Advanced Cluster Security FOR KubernetesAI | 6/7/2026 | 8/9/2026 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a… | |
| Aplazada | Media (4.8) | 0.32% | — | Ad-security AD MinerAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed locally. The pull request to fix this… | |
| Aplazada | Media (4.3) | 0.23% | — | Stormshield Network SecurityAI | 2/7/2026 | 2/7/2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH… | |
| Modificada | Media (5.3) | 0.30% | — | Elastic Endpoint Security | 1/7/2026 | 4/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Stormshield Network SecurityAI | 1/7/2026 | 1/7/2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain… | |
| Aplazada | Alta (8.6) | 0.38% | — | Bitfire SecurityAI | 26/6/2026 | 26/6/2026 | Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions. | |
| Pendiente de análisis | Alta (7.1) | 0.31% | — | Trellix Network Security CMAITrellix Network Security NXAI | 26/6/2026 | 29/9/2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details. | |
| Modificada | Media (4.3) | 0.25% | — | Jenkins Contrast Continuous Application Security | 24/6/2026 | 6/7/2026 | Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata. | |
| Aplazada | Media (5.4) | 0.14% | — | Jenkins Contrast Continuous Application SecurityAI | 24/6/2026 | 25/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API key, and service key. | |
| Modificada | Media (4.3) | 0.25% | — | Jenkins Contrast Continuous Application Security | 24/6/2026 | 6/7/2026 | A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key. | |
| Modificada | Alta (7.5) | 0.92% | — | Jenkins Script Security | 24/6/2026 | 27/8/2026 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates… | |
| Analizada | Alta (8.8) | 0.51% | — | Jenkins Script Security | 24/6/2026 | 26/6/2026 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection. | |
| Aplazada | Media (4.3) | 0.39% | — | Generate Security TXTAI | 24/6/2026 | 25/6/2026 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (5.9) | 0.47% | — | Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect… | |
| Aplazada | Baja (3.1) | 0.17% | — | Docker RegistryAIBlacklanternsecurity BbotAI | 17/6/2026 | 22/6/2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary… | |
| Aplazada | Alta (8.1) | 0.46% | — | Cloudsecure WP SecurityAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Anti-malware Security AND Brute-force FirewallAIPHPAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. | |
| Aplazada | Alta (7.1) | 0.12% | — | Qihoo 360 Total SecurityAI | 15/6/2026 | 24/7/2026 | A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach.… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Analizada | Media (4.4) | 0.09% | — | IBM Security Qradar EDR | 11/6/2026 | 1/10/2026 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user. | |
| En análisis | Alta (8.1) | 0.29% | — | Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace | 10/6/2026 | 23/7/2026 | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. | |
| Analizada | Alta (8.1) | 0.19% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24;… | |
| Analizada | Media (6.1) | 0.30% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation… | |
| Analizada | Media (5.3) | 0.18% | — | Vmware Spring Security | 10/6/2026 | 23/7/2026 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0… | |
| Analizada | Media (6.1) | 0.25% | — | Broadcom Spring Authorization ServerVmware Spring Security | 10/6/2026 | 23/7/2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected… |