Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | DLR Stable-baselines3AIPytorchAI | 20/9/2026 | 21/9/2026 | A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Alta (8.7) | 0.24% | — | Hulumi BaselineAI | 31/8/2026 | 31/8/2026 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring. | |
| Aplazada | Media (6.6) | 0.51% | — | Baseline-browser-mappingAI | 13/8/2026 | 9/9/2026 | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. | |
| Aplazada | Media (5.3) | 0.25% | — | Xtemos BaselAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in xtemos Basel basel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Basel: from n/a through <= 5.9.1. | |
| Modificada | Alta (8) | 0.35% | — | WUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx FirmwareWUT Com-server Highspeed 100baselx Firmware+12 | 13/12/2022 | 17/6/2026 | Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP… | |
| Modificada | Crítica (9.8) | 1.1% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 15/11/2022 | 17/6/2026 | Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request. | |
| Modificada | Alta (8.8) | 0.78% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 10/11/2022 | 17/6/2026 | Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user… | |
| Modificada | Media (5.4) | 0.46% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 10/11/2022 | 17/6/2026 | Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage | |
| Modificada | Media (6.1) | 99% | — | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Media (6.1) | 87% | — | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Alta (8.1) | 1.9% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Financial Services Basel Regulatory Capital Basic | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Portfolio, Attribution). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.1) | 3.1% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 10% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 41% | — | Honeywell Ademco Atnbaseloader100 ModuleMicrosoft Internet Explorer | 31/5/2007 | 16/6/2026 | Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and… | |
| Modificada | Media (4.3) | 1.2% | — | NMA Baseline CMS | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) PageID and (2) SiteNodeID parameters. | |
| Modificada | Alta (7.5) | 1.1% | — | NMA Baseline CMS | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter. | |
| Modificada | Media (5) | 3.2% | — | Microsoft Baseline Security Analyzer | 10/2/2004 | 16/6/2026 | Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | |
| Modificada | Media (5) | 16% | — | Microsoft Baseline Security Analyzer | 31/12/2002 | 16/6/2026 | Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java. |