Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.42%—PgvectorAI1/10/20262/10/2026
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
En análisisCrítica (9.2)0.27%—Simple-gitAISimple-git Argv-parserAI29/9/202630/9/2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A…
Pendiente de análisisAlta (8.8)0.10%—Google GvisorAI25/9/202625/9/2026
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character…
AplazadaMedia (5.3)0.16%—Gvectors WpforoAI25/9/202625/9/2026
The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI…
AplazadaMedia (6.4)0.20%—Gvectors WpforoAI25/9/202625/9/2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST['data'] array is copied into a $custom_fields…
AplazadaAlta (7.5)0.31%—Gvectors Wpforo ForumAI24/9/202624/9/2026
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before…
AplazadaMedia (6.5)0.22%—Gvectors Wpforo ForumAI23/9/202623/9/2026
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
AplazadaMedia (4.3)0.39%—Gvectors WpforoAI22/9/202623/9/2026
The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take…
AplazadaAlta (7.8)0.20%—Geovision Gv-remote E-mapAI17/9/202618/9/2026
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully…
Pendiente de análisisAlta (7)0.17%—Gnome GvfsAI10/9/20261/10/2026
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race…
AplazadaAlta (7.5)0.46%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.
AplazadaAlta (7.5)0.57%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.
AplazadaMedia (6.5)0.55%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
AplazadaAlta (7.5)0.55%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
AplazadaAlta (7.5)0.46%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
AplazadaCrítica (9.4)0.51%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.
AplazadaAlta (7.2)0.54%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
AplazadaMedia (4.9)0.44%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
AplazadaCrítica (9.8)0.48%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
AplazadaAlta (8.8)0.65%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.