Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
14.316 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.39% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would… | |
| Analizada | Media (6.5) | 0.47% | — | Linuxcontainers Incus | 7/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0. | |
| Modificada | Crítica (9.8) | 0.94% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/5/2026 | 8/10/2026 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability… | |
| Analizada | Alta (7.5) | 0.32% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service. | |
| Analizada | Alta (7.8) | 0.20% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs… | |
| Analizada | Alta (7.8) | 0.17% | — | ZTE Zxcloud Irai | 7/5/2026 | 17/6/2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | |
| Analizada | Alta (7.1) | 0.47% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic… | |
| Analizada | Baja (2.3) | 0.22% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate… | |
| Analizada | Alta (7.1) | 0.44% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer… | |
| Analizada | Alta (7.1) | 0.44% | — | Linuxcontainers Incus | 6/5/2026 | 17/6/2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic,… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Cisco Enterprise Chat AND EmailAI | 6/5/2026 | 17/6/2026 | A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. | |
| Analizada | Baja (2.9) | 0.53% | — | Flowiseai Flowise | 6/5/2026 | 17/6/2026 | A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is… | |
| Analizada | Media (5.3) | 0.44% | — | Flowiseai Flowise | 6/5/2026 | 17/6/2026 | A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The… | |
| Analizada | Media (6.3) | 0.37% | — | Flowiseai Flowise | 6/5/2026 | 17/6/2026 | A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can be launched remotely. A high complexity… | |
| Pendiente de análisis | Baja (2.7) | 0.22% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI está afectado por una Vulnerabilidad de disponibilidad continua de 'Texto de entrada' menos seguro. Un componente contiene una debilidad de seguridad en su implementación de manejo de entrada, aumentando el riesgo de configuración incorrecta y errores operativos. | |
| Pendiente de análisis | Alta (8.8) | 0.25% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI está afectado por una vulnerabilidad de Entrada de Comando No Validada / Contrabando Potencial de Comandos. Se identificó una falla en el manejo de la entrada de un componente que podría permitir la ejecución de comandos no autorizada. | |
| Analizada | Media (4.3) | 0.14% | — | Linuxcontainers LXC | 5/5/2026 | 24/7/2026 | lxc es un tiempo de ejecución de contenedores Linux. En el asistente setuid lxc-user-nic, la ruta de eliminación contiene un fallo lógico en la función find_line() que permite a un usuario sin privilegios eliminar interfaces de red conectadas a OVS que pertenecen a otros usuarios. Cuando lxc-user-nic delete escanea su… | |
| Analizada | Media (5.3) | 0.29% | — | Linuxcontainers Incus | 5/5/2026 | 24/7/2026 | Incus es un gestor de contenedores y máquinas virtuales de código abierto. En versiones anteriores a la 7.0.0, el flujo de importación de imágenes emite una solicitud HEAD saliente a una URL proporcionada por el usuario antes de validar la solicitud contra restricciones del proyecto como restricted.images.servers. La… | |
| Aplazada | Baja (1.2) | 0.29% | — | Chatchat-space Langchain-chatchatAI | 5/5/2026 | 24/7/2026 | Se encontró una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. El elemento afectado es la función _get_file_id del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente Gestor de Archivos Subidos. Realizar una manipulación resulta en valores insuficientemente… | |
| Aplazada | Baja (1.2) | 0.23% | — | Chatchat-space Langchain-chatchatAI | 5/5/2026 | 24/7/2026 | Se ha encontrado una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. Afectada es la función files del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente OpenAI-Compatible File Upload API. Dicha manipulación del argumento file.filename conduce a time-of-check… | |
| Aplazada | Baja (1.2) | 0.20% | — | Chatchat-space Langchain-chatchatAI | 5/5/2026 | 24/7/2026 | Se ha encontrado un fallo en chatchat-space Langchain-Chatchat hasta la versión 0.3.1.3. Este problema afecta a la función PIL.Image.tobytes del archivo libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py del componente Vision Chat Paste Image Gestor. Esta manipulación del argumento paste_image.image_data… | |
| Aplazada | Baja (2.1) | 0.49% | — | Chatchat-space Langchain-chatchatAI | 5/5/2026 | 24/7/2026 | Se detectó una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. Esta vulnerabilidad afecta a la función files/list_files/retrieve_file/retrieve_file_content/delete_file del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente Compatible File Service. La manipulación… | |
| Aplazada | Media (6.5) | 0.67% | — | EmailkitAI | 5/5/2026 | 17/6/2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/)… | |
| Analizada | Alta (7) | 0.05% | — | Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+96 | 4/5/2026 | 7/10/2026 | Corrupción de memoria durante la creación de un proceso en el procesador de señal digital debido a un fallo de asignación a nivel de kernel. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 7/10/2026 | DoS transitorio al procesar un marco de respuesta de Transición Rápida malformado con una estructura de encabezado inválida durante la itinerancia inalámbrica. |