Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11.345 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | — | — | Siemens NXAI | 2/10/2026 | 2/10/2026 | Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are… | |
| Aplazada | Media (6.1) | 0.21% | — | Wpsoul GreenshiftAI | 2/10/2026 | 2/10/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.1) | 0.19% | — | OpenscAI | 30/9/2026 | 1/10/2026 | A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called… | |
| Aplazada | Alta (8.6) | 0.27% | — | OpensaveAI | 30/9/2026 | 30/9/2026 | OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes. | |
| Aplazada | Media (6.3) | 0.22% | — | OpensaveAI | 30/9/2026 | 2/10/2026 | OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access… | |
| Aplazada | Baja (2.1) | 0.25% | — | Os4ed OpensisclassicAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.25% | — | Os4ed Opensls ClassicAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Baja (2.1) | 0.20% | — | Os4ed Opensis-classicAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack… | |
| Aplazada | Baja (2) | 0.33% | — | Os4ed OpensisclassicAI | 30/9/2026 | 1/10/2026 | A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote.… | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Wikimedia Mediawiki Flow ExtensionAI | 29/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (7.5) | 0.40% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID… | |
| Pendiente de análisis | Alta (7.5) | 0.23% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client… | |
| Pendiente de análisis | Alta (8.2) | 0.39% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The… | |
| Pendiente de análisis | Baja (3.7) | 0.24% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem… | |
| Pendiente de análisis | Media (5.3) | 0.39% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS… | |
| Pendiente de análisis | Media (5.3) | 0.22% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the… | |
| Pendiente de análisis | Media (5.3) | 0.35% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive… | |
| Pendiente de análisis | Alta (7.5) | 0.27% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from.… | |
| Pendiente de análisis | Baja (3.7) | 0.29% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | OpensslAI | 29/9/2026 | 30/9/2026 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains… | |
| Pendiente de análisis | Baja (3.7) | 0.26% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the… | |
| Pendiente de análisis | Media (5.3) | 0.33% | — | OpensslAI | 29/9/2026 | 30/9/2026 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the… | |
| Pendiente de análisis | Baja (3.7) | 0.36% | — | OpensslAI | 29/9/2026 | 30/9/2026 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact… | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | OpensslAI | 29/9/2026 | 30/9/2026 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in… | |
| Aplazada | Media (5.5) | 0.39% | — | Modsetter SurfsenseAI | 29/9/2026 | 1/10/2026 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The… |