Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.23% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination. | |
| Analizada | Alta (7.1) | 0.52% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken,… | |
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Analizada | Alta (8.8) | 0.76% | — | Nvidia Nemo Speech | 22/9/2026 | 29/9/2026 | NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Alta (7.8) | 0.39% | — | Nvidia Nemo Speech | 22/9/2026 | 29/9/2026 | NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 1.6% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Alta (8.3) | 0.24% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| Analizada | Alta (8.8) | 0.67% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Media (4.9) | 0.29% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (8.8) | 0.34% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Alta (8.8) | 0.57% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Analizada | Alta (8.1) | 0.44% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Analizada | Crítica (9.8) | 0.42% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 0.23% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| En análisis | Alta (8.8) | 0.20% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.45% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.67% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.8) | 0.25% | — | Nvidia Nemo Speech | 22/9/2026 | 25/9/2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.35% | — | Nvidia Nemo Speech | 22/9/2026 | 25/9/2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data… | |
| Analizada | Alta (7.8) | 0.35% | — | Nvidia Nemo Speech | 22/9/2026 | 25/9/2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Aplazada | Crítica (9.8) | 0.75% | — | ZlmediakitAI | 21/9/2026 | 24/9/2026 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are… |