Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.39% | — | Modsetter SurfsenseAI | 29/9/2026 | 1/10/2026 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.2% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Sortedset SharedAI | 21/7/2026 | 23/7/2026 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Sortedset SharedAI | 21/7/2026 | 22/7/2026 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow… | |
| Aplazada | Baja (2.3) | 0.20% | — | Mendi Neurofeedback Headset V4AI | 7/3/2026 | 16/8/2026 | A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the local network. The… | |
| Aplazada | Alta (8.7) | 3.9% | — | Avtech Cloudsetup.cgiAI | 9/10/2025 | 17/6/2026 | AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can… | |
| Aplazada | Alta (8.8) | 0.75% | — | DsetAI | 11/9/2024 | 14/7/2026 | Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the… | |
| Modificada | Alta (8.1) | 1.8% | — | Dset Project Dset | 1/5/2022 | 17/6/2026 | All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype… | |
| Modificada | Crítica (9.8) | 3.1% | — | Dset Project Dset | 29/12/2020 | 17/6/2026 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | |
| Modificada | Alta (7.5) | 6.7% | — | Sennheiser HeadsetupMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+5 | 9/11/2018 | 17/6/2026 | Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for… | |
| Modificada | Crítica (9.8) | 1.5% | — | Mext Ebidsettingchecker | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Baja (3.3) | 0.73% | — | Softbank Wi-fi Spot Configuration SoftwareSoftbank Mobile Wi-fi RouterSoftbank NEC 3G HandsetSoftbank Panasonic 3G Handset+9 | 17/6/2013 | 16/6/2026 | SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the… | |
| Modificada | Alta (9.3) | 3.1% | — | Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+21 | 21/4/2010 | 16/6/2026 | Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF… | |
| Modificada | Alta (7.5) | 0.95% | — | COM Soundset | 9/10/2009 | 16/6/2026 | SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php. | |
| Modificada | Alta (7.2) | 0.32% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions. | |
| Modificada | Alta (7.2) | 0.30% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to… | |
| Modificada | Media (4.3) | 0.58% | — | Vocera Wireless Handset | 3/3/2008 | 16/6/2026 | Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. | |
| Modificada | Alta (7.8) | 1.5% | — | Avaya Voip Handset | 18/10/2007 | 16/6/2026 | Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE… | |
| Modificada | Alta (7.8) | 1.5% | — | NEC Mobile Handset | 18/10/2007 | 16/6/2026 | Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE… | |
| Modificada | Alta (7.8) | 1.6% | — | LG Electronics LG Mobile Handset | 18/10/2007 | 16/6/2026 | Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier… | |
| Modificada | Media (5.4) | 0.56% | — | Plantronic Headset | 31/12/2006 | 16/6/2026 | The Bluetooth stack in the Plantronic Headset does not properly implement Non-pairable mode, which allows remote attackers to conduct unauthorized pair-up operations. | |
| Modificada | Media (5) | 1.7% | — | Nokia 6210 Handset | 7/3/2003 | 16/6/2026 | Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers. |