Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
2493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.28% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Aplazada | Media (6.3) | 0.21% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as… | |
| Aplazada | Alta (7.6) | 0.23% | — | Edgelesssys ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying… | |
| Aplazada | Alta (8.5) | 0.19% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes… | |
| Aplazada | Media (5.1) | 0.16% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when… | |
| Aplazada | Alta (8.5) | 0.21% | — | Edgelesssys ContrastAI | 27/9/2026 | 28/9/2026 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list… | |
| Aplazada | Alta (8.8) | 0.61% | — | Jazzware Rt1000 EdgeAI | 21/9/2026 | 22/9/2026 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over… | |
| Aplazada | Media (6.2) | 0.12% | — | Crmeb Knowledge-paid SystemAI | 21/9/2026 | 1/10/2026 | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information. | |
| Pendiente de análisis | Alta (8.1) | 0.62% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and… | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 29/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHeader.PayloadLen received through the CloudHub viaduct message-processing path and… | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Edge Chromium | 18/9/2026 | 24/9/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Crítica (9) | 0.70% | — | AnyqueryAIGoogle ChromeAIBraveAIMicrosoft EdgeAI+1 | 17/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript or… | |
| Pendiente de análisis | Alta (8.2) | 0.37% | — | Velocloud EdgeAIVelocloud GatewayAI | 16/9/2026 | 16/9/2026 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to terminate and restart, leading to a… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Vmware Velocloud EdgeAI | 16/9/2026 | 17/9/2026 | The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Velocloud EdgeAI | 16/9/2026 | 17/9/2026 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Edge Chromium | 15/9/2026 | 25/9/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Edge Chromium | 15/9/2026 | 25/9/2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Oracle Communications Cloud Native Core Security Edge Protection ProxyAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication… | |
| Analizada | Media (4.3) | 0.23% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges… | |
| Analizada | Media (5.3) | 0.42% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 25/9/2026 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to… | |
| Analizada | Media (5.5) | 0.54% | — | Arubanetworks Edgeconnect Sd-wan OrchestratorHPE Edgeconnect Operating System | 15/9/2026 | 28/9/2026 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system. |