Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.29% | — | Buddyboss PlatformAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | |
| Pendiente de análisis | Media (5.1) | 0.10% | — | Dell BossAI | 28/9/2026 | 28/9/2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Dell BossAI | 28/9/2026 | 28/9/2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to… | |
| Pendiente de análisis | Media (6.8) | 0.27% | — | Bosch Sensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}}… | |
| Pendiente de análisis | Alta (8) | 0.31% | — | Boschsensortec Coines SDKAI | 10/9/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | Bosch Bme690 SensorapiAI | 10/9/2026 | 10/9/2026 | An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping… | |
| Pendiente de análisis | Alta (8.4) | 0.19% | — | Bosch Sensortec Bhi385 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event… | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Bosch Sensortec Bhi360 SensorapiAI | 10/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875).… | |
| Aplazada | Media (4.3) | 0.29% | — | Xibosignage XiboAI | 31/8/2026 | 9/9/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability… | |
| Pendiente de análisis | Alta (7.5) | 0.58% | — | Redhat Jboss EAPAIRedhat WildflyAIRedhat UndertowAI | 31/8/2026 | 10/9/2026 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send… | |
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Aplazada | Alta (8.7) | 0.35% | — | Bosch Smart HomeAI | 26/8/2026 | 8/9/2026 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions. | |
| Aplazada | Media (5.3) | 0.34% | — | FibosearchAI | 22/8/2026 | 26/8/2026 | The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Cloudfoundry Bosh CLIAI | 21/8/2026 | 28/8/2026 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities | |
| Pendiente de análisis | Media (4.3) | 1.0% | — | Jboss MOD ClusterAI | 19/8/2026 | 20/8/2026 | A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by… | |
| Aplazada | Media (5.3) | 0.40% | — | Cityboss E-municipalityAI | 14/8/2026 | 26/8/2026 | Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204. | |
| Pendiente de análisis | Media (5.3) | 1.0% | — | WildflyAIJboss EAPAIRedhat UndertowAI | 11/8/2026 | 22/9/2026 | A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with… | |
| Pendiente de análisis | Alta (7.4) | 0.39% | — | Redhat Jboss EAPAI | 11/8/2026 | 6/10/2026 | A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations. | |
| Pendiente de análisis | Alta (7.5) | 0.55% | — | Jboss RemotingAI | 11/8/2026 | 25/9/2026 | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service. | |
| Pendiente de análisis | Alta (8.1) | 0.57% | — | Jboss EAPAIORB Networks ORBAI | 11/8/2026 | 25/9/2026 | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Jboss MarshallingAIInfinispanAI | 11/8/2026 | 25/9/2026 | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. | |
| Pendiente de análisis | Media (4.2) | 0.21% | — | Cloudfoundry Bosh AgentAI | 6/8/2026 | 18/8/2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0… | |
| Aplazada | Media (5.9) | 0.24% | — | FibosearchAI | 6/8/2026 | 12/8/2026 | Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… |