Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

14.316 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.39%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would…
AnalizadaMedia (6.5)0.47%—Linuxcontainers Incus7/5/202617/6/2026
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0.
ModificadaCrítica (9.8)0.94%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux7/5/20268/10/2026
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability…
AnalizadaAlta (7.5)0.32%—ZTE Zxcloud Irai7/5/202617/6/2026
A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.
AnalizadaAlta (7.8)0.20%—ZTE Zxcloud Irai7/5/202617/6/2026
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs…
AnalizadaAlta (7.8)0.17%—ZTE Zxcloud Irai7/5/202617/6/2026
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
AnalizadaAlta (7.1)0.47%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic…
AnalizadaBaja (2.3)0.22%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate…
AnalizadaAlta (7.1)0.44%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer…
AnalizadaAlta (7.1)0.44%—Linuxcontainers Incus6/5/202617/6/2026
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic,…
Pendiente de análisisMedia (4.3)0.13%—Cisco Enterprise Chat AND EmailAI6/5/202617/6/2026
A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent.
AnalizadaBaja (2.9)0.53%—Flowiseai Flowise6/5/202617/6/2026
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is…
AnalizadaMedia (5.3)0.44%—Flowiseai Flowise6/5/202617/6/2026
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The…
AnalizadaMedia (6.3)0.37%—Flowiseai Flowise6/5/202617/6/2026
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can be launched remotely. A high complexity…
Pendiente de análisisBaja (2.7)0.22%—HCL Bigfix RunbookaiAI6/5/20267/10/2026
HCL BigFix RunBookAI está afectado por una Vulnerabilidad de disponibilidad continua de 'Texto de entrada' menos seguro. Un componente contiene una debilidad de seguridad en su implementación de manejo de entrada, aumentando el riesgo de configuración incorrecta y errores operativos.
Pendiente de análisisAlta (8.8)0.25%—HCL Bigfix RunbookaiAI6/5/20267/10/2026
HCL BigFix RunBookAI está afectado por una vulnerabilidad de Entrada de Comando No Validada / Contrabando Potencial de Comandos. Se identificó una falla en el manejo de la entrada de un componente que podría permitir la ejecución de comandos no autorizada.
AnalizadaMedia (4.3)0.14%—Linuxcontainers LXC5/5/202624/7/2026
lxc es un tiempo de ejecución de contenedores Linux. En el asistente setuid lxc-user-nic, la ruta de eliminación contiene un fallo lógico en la función find_line() que permite a un usuario sin privilegios eliminar interfaces de red conectadas a OVS que pertenecen a otros usuarios. Cuando lxc-user-nic delete escanea su…
AnalizadaMedia (5.3)0.29%—Linuxcontainers Incus5/5/202624/7/2026
Incus es un gestor de contenedores y máquinas virtuales de código abierto. En versiones anteriores a la 7.0.0, el flujo de importación de imágenes emite una solicitud HEAD saliente a una URL proporcionada por el usuario antes de validar la solicitud contra restricciones del proyecto como restricted.images.servers. La…
AplazadaBaja (1.2)0.29%—Chatchat-space Langchain-chatchatAI5/5/202624/7/2026
Se encontró una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. El elemento afectado es la función _get_file_id del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente Gestor de Archivos Subidos. Realizar una manipulación resulta en valores insuficientemente…
AplazadaBaja (1.2)0.23%—Chatchat-space Langchain-chatchatAI5/5/202624/7/2026
Se ha encontrado una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. Afectada es la función files del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente OpenAI-Compatible File Upload API. Dicha manipulación del argumento file.filename conduce a time-of-check…
AplazadaBaja (1.2)0.20%—Chatchat-space Langchain-chatchatAI5/5/202624/7/2026
Se ha encontrado un fallo en chatchat-space Langchain-Chatchat hasta la versión 0.3.1.3. Este problema afecta a la función PIL.Image.tobytes del archivo libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py del componente Vision Chat Paste Image Gestor. Esta manipulación del argumento paste_image.image_data…
AplazadaBaja (2.1)0.49%—Chatchat-space Langchain-chatchatAI5/5/202624/7/2026
Se detectó una vulnerabilidad en chatchat-space Langchain-Chatchat hasta 0.3.1.3. Esta vulnerabilidad afecta a la función files/list_files/retrieve_file/retrieve_file_content/delete_file del archivo libs/chatchat-server/chatchat/server/api_server/openai_routes.py del componente Compatible File Service. La manipulación…
AplazadaMedia (6.5)0.67%—EmailkitAI5/5/202617/6/2026
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/)…
AnalizadaAlta (7)0.05%—Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+964/5/20267/10/2026
Corrupción de memoria durante la creación de un proceso en el procesador de señal digital debido a un fallo de asignación a nivel de kernel.
AnalizadaAlta (7.5)0.22%—Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+2534/5/20267/10/2026
DoS transitorio al procesar un marco de respuesta de Transición Rápida malformado con una estructura de encabezado inválida durante la itinerancia inalámbrica.