Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
3321 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.32% | — | Wpzoom ConnectAI | 3/10/2026 | 3/10/2026 | The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.3 via the 'x-yamidoo-signature (attacker-obtained via inline_js identify payload)' parameter. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.23% | — | Bytecore MCP Connector FOR AI ToolsAI | 1/10/2026 | 1/10/2026 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| Aplazada | Alta (8.8) | 0.38% | — | Bytecore Stack MCP Connector FOR AI ToolsAI | 1/10/2026 | 3/10/2026 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's… | |
| Aplazada | Media (5.4) | 0.22% | — | Allable ConnectorAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Connections-pro Connections Business DirectoryAI | 30/9/2026 | 30/9/2026 | The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including… | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | Nvidia ConnectxAINvidia BluefieldAI | 29/9/2026 | 29/9/2026 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service. | |
| En análisis | Media (5.9) | 0.14% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 29/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Media (5.4) | 0.15% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 29/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| En análisis | Alta (7.8) | 0.08% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 30/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Media (6.5) | 0.12% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 29/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks,… | |
| Pendiente de análisis | Baja (3.8) | 0.18% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 30/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering,… | |
| Pendiente de análisis | Media (4.7) | 0.11% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 30/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure,… | |
| Pendiente de análisis | Media (6.4) | 0.08% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 30/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information… | |
| Pendiente de análisis | Baja (3) | 0.09% | — | Dell Secure Connect GatewayAI | 29/9/2026 | 29/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized… | |
| Aplazada | Media (5.3) | 0.18% | — | Connect-xcorsAI | 28/9/2026 | 30/9/2026 | An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request. | |
| Aplazada | Media (5.3) | 0.25% | — | Trustedlogin ConnectorAI | 23/9/2026 | 23/9/2026 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | WSP MCP AI Agents ConnectorAI | 23/9/2026 | 23/9/2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | |
| Analizada | Alta (7.5) | 0.26% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.3) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection… | |
| Analizada | Alta (7.4) | 0.25% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (6.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection… | |
| Analizada | Media (6.4) | 0.11% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and… | |
| Analizada | Baja (3.7) | 0.16% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 26/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.4) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. | |
| Analizada | Media (6.8) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |