Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
1874 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | — | — | Confluent Kafka Python ClientAI | 1/10/2026 | 1/10/2026 | Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | |
| Pendiente de análisis | Alta (8.5) | 0.16% | — | Catonetworks SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe. | |
| Pendiente de análisis | Media (6.8) | 0.09% | — | Cato Windows SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement. | |
| Aplazada | Alta (8.7) | 0.57% | — | Codesys Gateway ClientAI | 30/9/2026 | 30/9/2026 | The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus… | |
| Pendiente de análisis | Alta (8.2) | 0.21% | — | Netx DUO Mqtt ClientAI | 29/9/2026 | 30/9/2026 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on… | |
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Pendiente de análisis | Alta (7.1) | 0.09% | — | Dell Trusted Device ClientAI | 24/9/2026 | 26/9/2026 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Aplazada | Alta (8.7) | 0.30% | — | BSV Wallet ToolboxAIBSV Wallet Toolbox ClientAIBSV Wallet Toolbox MobileAI | 24/9/2026 | 30/9/2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created… | |
| Aplazada | Media (6.5) | 0.11% | — | Fabasoft Folio ClientAIFabasoft Egov-suiteAI | 24/9/2026 | 26/9/2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Dell Inventory Collector ClientAI | 21/9/2026 | 24/9/2026 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI | 18/9/2026 | 21/9/2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling. | |
| Aplazada | Media (6.5) | 0.27% | — | Infinitewp ClientAI | 18/9/2026 | 18/9/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on… | |
| Pendiente de análisis | Media (5.9) | 0.27% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a… | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender… | |
| Pendiente de análisis | Media (5.9) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the… | |
| Pendiente de análisis | Media (6.8) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the… | |
| Pendiente de análisis | Alta (8.7) | 0.55% | — | Rabbitmq Java Client LibraryAI | 16/9/2026 | 24/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | Node-opcua-clientAI | 16/9/2026 | 24/9/2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitized field names and allows a __proto__.pollutedKey path to modify Object.prototype.… | |
| Aplazada | Alta (7) | 0.28% | — | Oracle HelidonAIOracle Helidon-dbclient-mongodbAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command. | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. |