Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9796 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | 0.22% | — | PhprojectAI | 2/10/2026 | 2/10/2026 | Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess()… | |
| Aplazada | Media (5.4) | 0.18% | — | Publishpress SeriesAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3. | |
| Aplazada | Media (5.4) | 0.34% | — | Filamentphp FilamentAI | 1/10/2026 | 2/10/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up… | |
| Aplazada | Media (6.9) | 0.18% | — | Simple-php-router Simple PHP RouterAI | 30/9/2026 | 1/10/2026 | simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted… | |
| Pendiente de análisis | Baja (2.7) | 0.23% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers… | |
| Pendiente de análisis | Baja (3) | 0.10% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. | |
| Pendiente de análisis | Baja (3.3) | 0.09% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. | |
| Pendiente de análisis | Media (4.1) | 0.09% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported… | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information… | |
| Pendiente de análisis | Media (4.9) | 0.31% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes… | |
| Pendiente de análisis | Media (6.4) | 0.10% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected… | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | HPE Instant ON APSAI | 29/9/2026 | 30/9/2026 | An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send… | |
| Pendiente de análisis | Media (6.6) | 0.42% | — | HPE Networking Instant ON APSAI | 29/9/2026 | 1/10/2026 | A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the… | |
| Pendiente de análisis | Alta (7.2) | 0.55% | — | HPE Networking Instant ON Access PointAI | 29/9/2026 | 1/10/2026 | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating… | |
| Pendiente de análisis | Alta (7.2) | 0.98% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Pendiente de análisis | Alta (8.1) | 0.36% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to… | |
| Pendiente de análisis | Crítica (9.6) | 0.32% | — | HPE Instant ONAI | 29/9/2026 | 1/10/2026 | A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code… | |
| Pendiente de análisis | Crítica (9.6) | 1.0% | — | HPE Instant ONAI | 29/9/2026 | 1/10/2026 | A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on… | |
| Pendiente de análisis | Crítica (9.6) | 0.31% | — | HPE Networking Instant ON APSAI | 29/9/2026 | 1/10/2026 | Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Pendiente de análisis | Crítica (9.8) | 0.54% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution. | |
| Pendiente de análisis | Crítica (9.8) | 0.56% | — | HPE Networking Instant ONAI | 29/9/2026 | 30/9/2026 | Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system. | |
| Pendiente de análisis | Baja (3.5) | 0.34% | — | Thephpleague FlysystemAI | 29/9/2026 | 30/9/2026 | Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return… | |
| Pendiente de análisis | Media (4.3) | 0.17% | — | HPE OneviewAI | 29/9/2026 | 29/9/2026 | A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. | |
| Pendiente de análisis | Alta (8.2) | 0.18% | — | HPE OneviewAI | 29/9/2026 | 29/9/2026 | A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. |