Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.41% | — | Projectdiscovery NucleiAI | 22/9/2026 | 23/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allows response content captured by an internal: true extractor in one protocol step… | |
| Pendiente de análisis | Media (5.5) | 0.17% | — | Projectdiscovery NucleiAI | 22/9/2026 | 28/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted unsigned workflow can therefore load a file-protocol template and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Projectdiscovery NucleiAI | 22/9/2026 | 25/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option. An untrusted javascript: template scanning an attacker-controlled… | |
| Pendiente de análisis | Media (4.7) | 0.18% | — | Projectdiscovery NucleiAI | 22/9/2026 | 24/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | Tanium DiscoverAI | 16/9/2026 | 18/9/2026 | Tanium addressed an information disclosure vulnerability in Discover. | |
| Pendiente de análisis | Alta (7) | 0.12% | — | Projectdiscovery NucleiAI | 16/9/2026 | 24/9/2026 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system… | |
| Pendiente de análisis | Alta (7.4) | 0.94% | — | Microsoft Discovery StudioAI | 3/9/2026 | 8/9/2026 | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Purview Ediscovery | 7/8/2026 | 7/8/2026 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft In-memory Project Discovery | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.… | |
| Aplazada | Alta (7.5) | 0.61% | — | Steeltoe Discovery EurekaAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than `"MyOwn"` or `"Amazon"`, despite the Java… | |
| Modificada | Crítica (9.2) | 6.5% | — | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Analizada | Alta (8.7) | 0.73% | — | Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+1 | 9/6/2026 | 24/7/2026 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by… | |
| Modificada | Crítica (9.2) | 2.7% | — | F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+8 | 22/5/2026 | 25/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple… | |
| Analizada | Media (5.5) | 0.16% | — | Projectdiscovery Nuclei | 8/5/2026 | 17/6/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This… | |
| Analizada | Media (5.3) | 0.44% | — | Projectdiscovery Nuclei | 8/5/2026 | 17/6/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing… | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Purview Ediscovery | 23/4/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.43% | — | Projectdiscovery Nuclei | 20/4/2026 | 17/6/2026 | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration). | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpdiscover Timeline Event HistoryAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Reflected XSS.This issue affects Timeline Event History: from n/a through <= 3.2. | |
| Analizada | Media (6.5) | 0.35% | — | Tanium Discover | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Discover. | |
| Analizada | Media (6.3) | 0.28% | — | Tanium Discover | 5/2/2026 | 17/6/2026 | Tanium addressed an improper input validation vulnerability in Discover. | |
| Aplazada | Alta (8.9) | 0.61% | — | Westerndigital WD DiscoveryAI | 26/1/2026 | 17/6/2026 | DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in the installer's search path. | |
| Analizada | Media (6.5) | 0.39% | — | Tanium Discover | 26/1/2026 | 17/6/2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Discover. | |
| Analizada | Media (4.9) | 0.44% | — | Tanium Discover | 26/1/2026 | 17/6/2026 | Tanium addressed an improper input validation vulnerability in Discover. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpdiscover Accordion Slider GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7. |