Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
602 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Parsi DateAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | GO Live Update UrlsAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | |
| Aplazada | Media (5.9) | 0.16% | — | Tauri Updater PluginAI | 23/9/2026 | 23/9/2026 | The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check… | |
| Aplazada | Media (6.8) | 0.45% | — | Tauri UpdaterAI | 22/9/2026 | 22/9/2026 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any… | |
| Aplazada | Alta (8.5) | 0.18% | — | Biostar Bios Update UtilityAI | 21/9/2026 | 22/9/2026 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been… | |
| Pendiente de análisis | Alta (8.2) | 0.19% | — | Dell Server Update UtilityAI | 17/9/2026 | 19/9/2026 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (8.8) | 0.41% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (6) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Media (6) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (4.3) | 0.37% | — | Robots ValidateAI | 4/9/2026 | 8/9/2026 | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching the rule's domain, and issues a forward… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Update-center2AI | 2/9/2026 | 3/9/2026 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Aplazada | Alta (8.7) | 0.66% | — | Gitoxide GIXAIGitoxide Gix-validateAI | 28/8/2026 | 31/8/2026 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Time4 PopcornAITime4 Popcorn Updater.exeAITime4 Popcorn Pt.upddAI | 27/8/2026 | 1/9/2026 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components | |
| Analizada | Media (6.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.3) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.3) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (6.6) | 0.17% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.31% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |