Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 1.4% | — | Amazon Sagemaker DistributionAI | 2/10/2026 | 6/10/2026 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated… | |
| Aplazada | Alta (8.7) | 0.66% | — | Internlm LmdeployAIDistserveAI | 17/9/2026 | 22/9/2026 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler… | |
| Aplazada | Alta (7.5) | 0.44% | — | Distribution ManagementAI | 8/9/2026 | 9/9/2026 | An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Labor Distribution | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful… | |
| Aplazada | Alta (8.2) | 0.18% | — | Proot-distroAI | 29/7/2026 | 30/7/2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore… | |
| Aplazada | Alta (8.2) | 0.19% | — | Proot-distroAI | 29/7/2026 | 30/7/2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating… | |
| Pendiente de análisis | Alta (8) | 0.40% | — | Kubeflow Community DistributionAIKubeflow PlatformAI | 21/7/2026 | 23/7/2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs,… | |
| Aplazada | Baja (3.7) | 0.22% | — | Powerdns DnsdistAI | 25/6/2026 | 25/6/2026 | An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter. | |
| Analizada | Media (6.3) | 0.29% | — | Distribution | 14/5/2026 | 17/6/2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Analizada | Alta (7.7) | 0.81% | — | Redistimeseries | 5/5/2026 | 25/7/2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can… | |
| Analizada | Alta (8.2) | 1.2% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service. | |
| Analizada | Alta (8.1) | 0.80% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default. | |
| Analizada | Crítica (9.1) | 2.8% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache. | |
| Analizada | Alta (7.5) | 0.75% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | PRSD detection denial of service | |
| Analizada | Media (6.5) | 0.39% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend. | |
| Analizada | Alta (7.5) | 0.80% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection. | |
| Analizada | Alta (7.5) | 0.80% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. | |
| Analizada | Alta (7.5) | 0.82% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. | |
| Analizada | Alta (7.5) | 0.80% | — | Powerdns Dnsdist | 22/4/2026 | 17/6/2026 | An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default. | |
| Analizada | Alta (7.5) | 1.1% | — | Powerdns AuthoritativePowerdns DnsdistPowerdns Recursor | 22/4/2026 | 17/6/2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. | |
| Analizada | Alta (7.5) | 1.1% | — | Powerdns AuthoritativePowerdns DnsdistPowerdns Recursor | 22/4/2026 | 17/6/2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. | |
| Aplazada | Media (6.5) | 0.22% | — | Manoj Kumar MK Google-directionsAIManoj Kumar MK Google-distance-calculatorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1. | |
| Modificada | Alta (7.5) | 0.67% | — | Distribution | 6/4/2026 | 9/9/2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but… |