Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.31% | — | Quest DocaveAIQuest PerimeterAIQuest Compliance GuardianAI | 26/9/2025 | 17/6/2026 | Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is… | |
| Aplazada | Alta (7.3) | 0.15% | — | Nvidia DocaAI | 4/9/2025 | 17/6/2026 | NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate privileges. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Alta (7.3) | 0.15% | — | Nvidia DocaAI | 4/9/2025 | 30/9/2026 | NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Alta (7.6) | 0.18% | — | Nvidia Doca-hostAIMellanox OfedAI | 17/7/2025 | 17/6/2026 | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN. | |
| Analizada | Media (5.3) | 0.69% | — | Linuxfoundation Docarray | 25/5/2025 | 17/6/2026 | A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype… | |
| Analizada | Alta (7.5) | 69% | — | Jhpyle Docassemble | 21/3/2024 | 17/6/2026 | Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch. | |
| Analizada | Media (6.1) | 0.41% | — | Jhpyle Docassemble | 21/3/2024 | 17/6/2026 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open redirect. The vulnerability has been patched in version 1.4.97 of the master branch. | |
| Analizada | Media (6.1) | 0.43% | — | Jhpyle Docassemble | 21/3/2024 | 17/6/2026 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML into a field, including the field for the user's name, and then that HTML could be displayed on the screen as HTML. The vulnerability has been patched in version 1.4.97 of the master branch. |