Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
21.080 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Media (6.2) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read… | |
| Modificada | Alta (7.5) | 0.53% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (7.5) | 0.37% | — | Apple IpadosApple Iphone OS | 11/5/2026 | 17/6/2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging. | |
| Analizada | Alta (7.5) | 0.54% | — | Apple IpadosApple Iphone OS | 11/5/2026 | 17/6/2026 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service. | |
| Analizada | Alta (7.5) | 0.50% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain. | |
| Analizada | Alta (7.5) | 0.58% | — | Apple Macos | 11/5/2026 | 17/6/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination. | |
| Modificada | Alta (8.8) | 0.51% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 15/7/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Alta (7.5) | 0.87% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination. | |
| Analizada | Alta (7.8) | 0.15% | — | Apple Macos | 11/5/2026 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. An app may be able to gain root privileges. | |
| Analizada | Media (4.7) | 0.10% | — | Apple Macos | 11/5/2026 | 17/6/2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. | |
| Analizada | Media (5.4) | 0.37% | — | Apple IpadosApple Iphone OSApple Macos | 11/5/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to execute arbitrary code with kernel privileges. | |
| Analizada | Media (5.5) | 0.12% | — | Apple Macos | 11/5/2026 | 4/9/2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data. | |
| Aplazada | Alta (8.6) | 0.41% | — | Meari IOT SDKAIMeari CloudedgeAIArentiAIMeari Android APPAI | 11/5/2026 | 17/6/2026 | In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys. | |
| Aplazada | Alta (7.5) | 0.41% | — | Meari Client ApplicationsAIMeari CloudedgeAIMeari ArentiAI | 11/5/2026 | 17/6/2026 | In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is a server-side authorization… | |
| Aplazada | Baja (2.9) | 0.44% | — | Industrial Application Software IAS Canias ERPAI | 10/5/2026 | 24/7/2026 | Se encontró una vulnerabilidad en el software de aplicación industrial IAS Canias ERP 8.03. El elemento afectado es la función doAction del componente Login RMI Interface. Realizar una manipulación resulta en una discrepancia observable en la respuesta. El ataque es posible de llevar a cabo de forma remota. Se… | |
| Aplazada | Media (5.5) | 0.68% | — | Industrial Application Software IAS Canias ERPAI | 10/5/2026 | 24/7/2026 | Se encontró una vulnerabilidad en el software de aplicación industrial IAS Canias ERP 8.03. Esto afecta la función doAction del componente RMI Interface. La manipulación del argumento sessionId resulta en autenticación indebida. Es posible lanzar el ataque remotamente. El exploit se ha hecho público y podría ser… | |
| Pendiente de análisis | Media (5.3) | 0.08% | — | Ezviz APPAIEzviz Cloud Feature ModulesAI | 9/5/2026 | 25/7/2026 | Algunos productos EZVIZ utilizan versiones antiguas de módulos de funciones en la nube con interfaces de API heredadas, lo que plantea un riesgo de transmisión de datos. Los atacantes pueden explotar esto al interceptar solicitudes de red para obtener datos. Se aconseja a los usuarios que actualicen la aplicación a la… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de falta de autorización en HCL BigFix WebUI permite a un usuario autenticado sin los permisos adecuados ver información ambiental sensible mediante acceso directo a la URL de la página no autorizada. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de autorización impropia en HCL BigFix WebUI permite a un usuario autenticado sin privilegios de Operador Maestro acceder a datos internos (nombres de sitios, versiones y variables de configuración) y eludir los requisitos de privilegios a través de puntos finales desprotegidos que carecen de… | |
| Analizada | Crítica (9.8) | 0.79% | — | Snipeitapp Snipe-it | 7/5/2026 | 17/6/2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component | |
| Aplazada | Media (6) | 0.27% | — | Wallosapp WallosAI | 7/5/2026 | 17/6/2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user. Any normal user can fully control a webhook URL, headers, and body, then use Wallos to send… | |
| Aplazada | Alta (7.7) | 0.39% | — | Wallosapp WallosAI | 7/5/2026 | 17/6/2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS rebinding TOCTOU… | |
| Aplazada | Media (4.3) | 0.33% | — | Wallosapp WallosAI | 7/5/2026 | 17/6/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in endpoints/subscription/add.php (line 42) and endpoints/payments/add.php (line 40) uses an inline IP validation check (FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) that does not block CGNAT… | |
| Aplazada | Media (5.3) | 0.33% | — | Wedevs Happy Addons FOR ElementorAI | 7/5/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8. |