Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Amazon Awslabs.dynamodb-mcp-serverAI | 4/9/2026 | 8/9/2026 | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model… | |
| Analizada | Alta (8.2) | 0.69% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | |
| Analizada | Media (5.3) | 0.46% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Media (6.5) | 0.41% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering. | |
| Analizada | Media (6.5) | 0.41% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Analizada | Alta (8.1) | 0.77% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.56% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.82% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7.5) | 0.55% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering. | |
| Analizada | Crítica (9.8) | 0.89% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Analizada | Alta (8.2) | 0.64% | — | Nvidia Dynamo | 4/8/2026 | 7/8/2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. | |
| Aplazada | Baja (3.7) | 0.24% | — | Amazon AWS SDK FOR .netAIAmazon S3AIAmazon DynamodbAIAmazon GlacierAI | 10/1/2026 | 17/6/2026 | AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related… | |
| Modificada | Crítica (9.8) | 1.9% | — | Dynamoosejs Dynamoose | 8/2/2021 | 17/6/2026 | Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We… | |
| Modificada | Alta (7.8) | 0.38% | — | Autodesk Dynamo BIM | 17/4/2020 | 17/6/2026 | An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files. | |
| Modificada | Media (5) | 6.4% | — | Ecometry Sgdynamo | 29/5/2002 | 16/6/2026 | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter. | |
| Modificada | Media (5) | 1.1% | — | Sybase Powerdynamo | 11/4/2000 | 16/6/2026 | The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack. |