Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Temporalio Tchannel-goAI | 21/9/2026 | 22/9/2026 | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can supply such a malformed call fragment, including as a… | |
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Temporalio Tchannel-goAI | 21/9/2026 | 22/9/2026 | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksum type. The parser uses that value as an index into a… | |
| Aplazada | Media (5.5) | 0.69% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.50% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch… | |
| Aplazada | Baja (2.1) | 0.37% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 19/9/2026 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Media (5.5) | 0.55% | — | Jaychouchannel Tourism-management-systemAI | 7/9/2026 | 8/9/2026 | A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName… | |
| Aplazada | Media (5.5) | 0.45% | — | Jaychouchannel Tourism Management SystemAI | 7/9/2026 | 8/9/2026 | A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel… | |
| Pendiente de análisis | Media (6.4) | 0.33% | — | Multicloud-operators ChannelAI | 12/8/2026 | 5/9/2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in… | |
| Aplazada | Media (6.6) | 0.54% | — | Sse-channelAI | 12/5/2026 | 17/6/2026 | sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, implementations that allow user-provided values to be passed to event, retry or id fields are susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream. This… | |
| Analizada | Media (5.5) | 0.31% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.3) | 0.70% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Modificada | Alta (8.8) | 0.30% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.8) | 0.33% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/5/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |