Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
14.316 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 7/10/2026 | DoS transitorio al procesar tablas de tasas de potencia objetivo durante la configuración del canal. | |
| Aplazada | Baja (2.1) | 0.38% | — | Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.41% | — | Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.65% | — | Yunaiv Yudao CloudAI | 3/5/2026 | 17/6/2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be… | |
| Aplazada | Baja (2.1) | 0.32% | — | Youlai-bootAI | 3/5/2026 | 17/6/2026 | A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection. The attack may be… | |
| Aplazada | Alta (7.1) | 0.37% | — | Paidmembershipspro Paid Memberships PROAI | 2/5/2026 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`, `wp_ajax_pmpro_stripe_delete_webhook`, and… | |
| Aplazada | Alta (8.8) | 0.56% | — | WP Mail GatewayAI | 2/5/2026 | 17/6/2026 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and… | |
| Aplazada | Media (5.5) | 2.1% | — | Sunwood AI Labs Command Executor MCP ServerAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (6.5) | 0.32% | — | Apple Container | 30/4/2026 | 17/6/2026 | Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3. | |
| Analizada | Alta (7.5) | 0.81% | — | Amazon ECS Container Agent | 30/4/2026 | 17/6/2026 | Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a specially crafted username… | |
| Modificada | Alta (7.4) | 0.89% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 8/10/2026 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate… | |
| Modificada | Baja (3.7) | 0.85% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 28/9/2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly… | |
| Modificada | Crítica (9.1) | 0.89% | — | GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 8/10/2026 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service. | |
| Analizada | Alta (7.5) | 0.44% | — | Jetbrains Intellij Idea | 30/4/2026 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | |
| Analizada | Media (5.9) | 0.27% | — | Apache Airflow | 30/4/2026 | 17/6/2026 | Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and… | |
| Aplazada | Baja (2.1) | 0.45% | 💥 PoC | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 29/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site… | |
| Analizada | Alta (8.8) | 0.29% | — | Sailpoint Identityiq | 29/4/2026 | 17/6/2026 | This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing. | |
| Aplazada | Media (5.5) | 0.62% | — | Fatbobman Mail-mcp-bridgeAI | 29/4/2026 | 17/6/2026 | A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the argument message_ids can lead to path traversal. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version… | |
| Analizada | Alta (7.8) | 0.15% | — | Entechtaiwan Tvicport | 29/4/2026 | 17/6/2026 | An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending crafted IOCTL 0x80002008 requests. | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce SpectraAIBrainstormforce Ultimate-addons-for-gutenbergAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22. | |
| Aplazada | Alta (7.3) | 0.30% | — | Brainstormforce Sureforms PROAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | Dell Disk Library FOR MainframeAI | 29/4/2026 | 25/7/2026 | Dell Disk Library para Mainframe, versión(es) DLm 8700/2700 contiene una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). Un atacante con privilegios bajos con acceso remoto podría potencialmente explotar esta vulnerabilidad, lo que llevaría a una falsificación de petición del lado del… | |
| Aplazada | Media (5.5) | 2.1% | — | Eiliyaabedini Aider-mcpAI | 28/4/2026 | 24/7/2026 | Se ha encontrado una vulnerabilidad en eiliyaabedini aider-mcp hasta 667b914301aada695aab0e46d1fb3a7d5e32c8af. Afecta a una función desconocida del archivo aider_mcp.py del componente code_with_ai. La manipulación del argumento working_dir/editable_files conduce a inyección de comandos. El ataque puede iniciarse de… | |
| Aplazada | Media (6.1) | 0.44% | 💥 PoC | Mahmoudai1 School Management SystemAI | 28/4/2026 | 20/7/2026 | Una vulnerabilidad de cross-site scripting (XSS) reflejada en School Management System de mahmoudai1 permite a atacantes remotos no autenticados ejecutar JavaScript arbitrario en los navegadores de la víctima a través del parámetro 'type' no sanitizado en register.PHP. | |
| Modificada | Crítica (9.8) | 0.74% | — | Apache Pony Mail | 28/4/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development under the name "Pony… |