Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

14.316 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.22%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2414/5/20267/10/2026
DoS transitorio al procesar tablas de tasas de potencia objetivo durante la configuración del canal.
AplazadaBaja (2.1)0.38%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit…
AplazadaMedia (5.5)0.41%—Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The…
AplazadaMedia (5.5)0.65%—Yunaiv Yudao CloudAI3/5/202617/6/2026
A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be…
AplazadaBaja (2.1)0.32%—Youlai-bootAI3/5/202617/6/2026
A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection. The attack may be…
AplazadaAlta (7.1)0.37%—Paidmembershipspro Paid Memberships PROAI2/5/202617/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and…
AplazadaAlta (8.8)0.56%—WP Mail GatewayAI2/5/202617/6/2026
The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and…
AplazadaMedia (5.5)2.1%—Sunwood AI Labs Command Executor MCP ServerAI1/5/202617/6/2026
A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaMedia (6.5)0.32%—Apple Container30/4/202617/6/2026
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
AnalizadaAlta (7.5)0.81%—Amazon ECS Container Agent30/4/202617/6/2026
Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a specially crafted username…
ModificadaAlta (7.4)0.89%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux30/4/20268/10/2026
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate…
ModificadaBaja (3.7)0.85%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux30/4/202628/9/2026
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly…
ModificadaCrítica (9.1)0.89%—GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux30/4/20268/10/2026
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
AnalizadaAlta (7.5)0.44%—Jetbrains Intellij Idea30/4/202617/6/2026
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
AnalizadaMedia (5.9)0.27%—Apache Airflow30/4/202617/6/2026
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and…
AplazadaBaja (2.1)0.45%💥 PoCSourcecodester CET Automated Grading System With AI Predictive AnalyticsAI29/4/202617/6/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site…
AnalizadaAlta (8.8)0.29%—Sailpoint Identityiq29/4/202617/6/2026
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.
AplazadaMedia (5.5)0.62%—Fatbobman Mail-mcp-bridgeAI29/4/202617/6/2026
A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the argument message_ids can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version…
AnalizadaAlta (7.8)0.15%—Entechtaiwan Tvicport29/4/202617/6/2026
An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending crafted IOCTL 0x80002008 requests.
AplazadaMedia (4.3)0.27%—Brainstormforce SpectraAIBrainstormforce Ultimate-addons-for-gutenbergAI29/4/202617/6/2026
Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.
AplazadaAlta (7.3)0.30%—Brainstormforce Sureforms PROAI29/4/202617/6/2026
Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.
Pendiente de análisisMedia (4.3)0.24%—Dell Disk Library FOR MainframeAI29/4/202625/7/2026
Dell Disk Library para Mainframe, versión(es) DLm 8700/2700 contiene una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). Un atacante con privilegios bajos con acceso remoto podría potencialmente explotar esta vulnerabilidad, lo que llevaría a una falsificación de petición del lado del…
AplazadaMedia (5.5)2.1%—Eiliyaabedini Aider-mcpAI28/4/202624/7/2026
Se ha encontrado una vulnerabilidad en eiliyaabedini aider-mcp hasta 667b914301aada695aab0e46d1fb3a7d5e32c8af. Afecta a una función desconocida del archivo aider_mcp.py del componente code_with_ai. La manipulación del argumento working_dir/editable_files conduce a inyección de comandos. El ataque puede iniciarse de…
AplazadaMedia (6.1)0.44%💥 PoCMahmoudai1 School Management SystemAI28/4/202620/7/2026
Una vulnerabilidad de cross-site scripting (XSS) reflejada en School Management System de mahmoudai1 permite a atacantes remotos no autenticados ejecutar JavaScript arbitrario en los navegadores de la víctima a través del parámetro 'type' no sanitizado en register.PHP.
ModificadaCrítica (9.8)0.74%—Apache Pony Mail28/4/202617/6/2026
** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony…