Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.39% | — | Nextcloud ServerAINextcloud Enterprise ServerAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporary part files during… | |
| Aplazada | Baja (2.6) | 0.31% | — | Nextcloud ServerAINextcloud Enterprise ServerAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circles. Since circle IDs have 62^15 complexity by default this is still… | |
| Analizada | Alta (8.8) | 0.38% | — | Elastic Cloud Enterprise | 7/11/2025 | 17/6/2026 | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is: post:/platform/configuration/security/service-accounts… | |
| Analizada | Alta (7.2) | 0.66% | — | Elastic Cloud Enterprise | 13/10/2025 | 1/10/2026 | Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated. | |
| Analizada | Crítica (9.8) | 0.60% | — | Elastic Cloud Enterprise | 28/6/2024 | 17/6/2026 | It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges. | |
| Modificada | Alta (7.5) | 2.1% | — | ElasticsearchElastic Cloud Enterprise | 26/10/2023 | 17/6/2026 | An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication… | |
| Modificada | Alta (7.8) | 0.19% | — | Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite | 3/8/2023 | 17/6/2026 | Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator. | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Enterprise ServerNextcloud ServerFedoraproject Fedora | 25/11/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or… | |
| Modificada | Media (6.5) | 0.50% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a… | |
| Modificada | Media (4.3) | 0.91% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of… | |
| Modificada | Media (5.3) | 0.67% | — | Nextcloud Enterprise ServerNextcloud Server | 27/10/2022 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and… | |
| Modificada | Media (5.3) | 0.64% | — | Elastic Cloud Enterprise | 28/9/2022 | 17/6/2026 | A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment logs in the Logging and Monitoring cluster. | |
| Modificada | Alta (7.8) | 0.23% | — | Fabasoft Cloud Enterprise Client | 19/9/2022 | 17/6/2026 | The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation. | |
| Modificada | Media (5.3) | 0.95% | — | Nextcloud Enterprise ServerNextcloud Server | 16/9/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to… | |
| Modificada | Alta (7.5) | 0.76% | — | Nextcloud Enterprise ServerNextcloud Server | 15/9/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7… | |
| Modificada | Media (6.5) | 0.80% | — | Elastic Cloud Enterprise | 25/8/2022 | 17/6/2026 | A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster. The affected APIs are PATCH /api/v1/user and PATCH… | |
| Modificada | Media (5.3) | 0.90% | — | Elastic Cloud Enterprise | 19/9/2018 | 17/6/2026 | In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other… | |
| Modificada | Alta (7.5) | 0.60% | — | Elastic Cloud Enterprise | 19/9/2018 | 17/6/2026 | Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster… | |
| Modificada | Media (5.9) | 0.65% | — | Elastic Cloud Enterprise | 19/9/2018 | 17/6/2026 | In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would… | |
| Modificada | Media (5.9) | 0.57% | — | Elasticsearch Cloud Enterprise | 29/9/2017 | 17/6/2026 | The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data. |