Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

5089 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.55%—Redhat Advanced Cluster Security FOR KubernetesAI6/7/20268/9/2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a…
AplazadaMedia (4.8)0.32%—Ad-security AD MinerAI5/7/20266/7/2026
A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed locally. The pull request to fix this…
AplazadaMedia (4.3)0.23%—Stormshield Network SecurityAI2/7/20262/7/2026
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH…
ModificadaMedia (5.3)0.30%—Elastic Endpoint Security1/7/20264/9/2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Pendiente de análisisMedia (4.3)0.13%—Stormshield Network SecurityAI1/7/20261/7/2026
A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain…
AplazadaAlta (8.6)0.38%—Bitfire SecurityAI26/6/202626/6/2026
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
Pendiente de análisisAlta (7.1)0.31%—Trellix Network Security CMAITrellix Network Security NXAI26/6/202629/9/2026
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.
ModificadaMedia (4.3)0.25%—Jenkins Contrast Continuous Application Security24/6/20266/7/2026
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
AplazadaMedia (5.4)0.14%—Jenkins Contrast Continuous Application SecurityAI24/6/202625/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
ModificadaMedia (4.3)0.25%—Jenkins Contrast Continuous Application Security24/6/20266/7/2026
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
ModificadaAlta (7.5)0.92%—Jenkins Script Security24/6/202627/8/2026
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates…
AnalizadaAlta (8.8)0.51%—Jenkins Script Security24/6/202626/6/2026
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
AplazadaMedia (4.3)0.39%—Generate Security TXTAI24/6/202625/6/2026
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (5.9)0.47%—Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect…
AplazadaBaja (3.1)0.17%—Docker RegistryAIBlacklanternsecurity BbotAI17/6/202622/6/2026
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary…
AplazadaAlta (8.1)0.46%—Cloudsecure WP SecurityAI15/6/202617/6/2026
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
AplazadaAlta (8.8)0.52%—Anti-malware Security AND Brute-force FirewallAIPHPAI15/6/202617/6/2026
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
AplazadaAlta (7.1)0.12%—Qihoo 360 Total SecurityAI15/6/202624/7/2026
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach.…
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AnalizadaMedia (4.4)0.09%—IBM Security Qradar EDR11/6/20261/10/2026
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
En análisisAlta (8.1)0.29%—Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace10/6/202623/7/2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
AnalizadaAlta (8.1)0.19%—Vmware Spring Security10/6/202623/7/2026
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24;…
AnalizadaMedia (6.1)0.30%—Vmware Spring Security10/6/202623/7/2026
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation…
AnalizadaMedia (5.3)0.18%—Vmware Spring Security10/6/202623/7/2026
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0…
AnalizadaMedia (6.1)0.25%—Broadcom Spring Authorization ServerVmware Spring Security10/6/202623/7/2026
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected…