Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 563 respecto a la semana anterior
Críticas / altas1444▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
8414 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.4) | — | — | Discord LibdaveAI | 2/10/2026 | 2/10/2026 | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected… | |
| Aplazada | Crítica (9.2) | 0.55% | — | PiscinaAI | 30/9/2026 | 30/9/2026 | piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive… | |
| Aplazada | Alta (7.6) | 0.38% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Analizada | Crítica (9.8) | 1.1% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 1/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Aplazada | Baja (2.1) | 0.33% | — | Os4ed OpensisclassicAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Baja (2) | 0.33% | — | Os4ed OpensisclassicAI | 30/9/2026 | 1/10/2026 | A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote.… | |
| Aplazada | Media (5.3) | 0.18% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels… | |
| Aplazada | Media (6) | 0.28% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured… | |
| Aplazada | Media (5) | 0.26% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and send chat content could place markup in a filename that was then interpreted by chat… | |
| Aplazada | Media (5.4) | 0.20% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat summaries. A user with standard posting privileges could create a post for an… | |
| Aplazada | Media (6.4) | 0.20% | — | DiscourseAI | 24/9/2026 | 28/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the… | |
| Aplazada | Media (5.4) | 0.22% | — | DiscourseAI | 24/9/2026 | 29/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src contained encoded userinfo. The sanitizer validated a decoded form differently from the… | |
| Aplazada | Media (6.5) | 0.29% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unrelated upload records instead of matching a literal identifier. The affected upload… | |
| Aplazada | Media (4.3) | 0.14% | — | DiscourseAI | 24/9/2026 | 29/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL whose allowlisted suffix appeared after a URL authority separator. The wildcard origin check matched the allowed domain… | |
| Aplazada | Alta (7.2) | 0.29% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pass an allowed_iframes subpath check while browser URL normalization… | |
| Aplazada | Alta (8.7) | 0.26% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the… | |
| Aplazada | Media (4.2) | 0.24% | — | Discourse AIAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Projectdiscovery NucleiAI | 22/9/2026 | 23/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allows response content captured by an internal: true extractor in one protocol step… | |
| Pendiente de análisis | Media (5.5) | 0.17% | — | Projectdiscovery NucleiAI | 22/9/2026 | 28/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted unsigned workflow can therefore load a file-protocol template and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Projectdiscovery NucleiAI | 22/9/2026 | 25/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option. An untrusted javascript: template scanning an attacker-controlled… | |
| Pendiente de análisis | Media (4.7) | 0.18% | — | Projectdiscovery NucleiAI | 22/9/2026 | 24/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an… | |
| Aplazada | Media (5.4) | 0.29% | — | DiscourseAI | 21/9/2026 | 23/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display name could persist markup in post action descriptions. Viewing the… | |
| Pendiente de análisis | Crítica (10) | 0.58% | — | Cisco ISEAICisco Ise-picAI | 16/9/2026 | 17/9/2026 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by… | |
| Pendiente de análisis | Crítica (9.1) | 0.56% | — | Cisco ISEAI | 16/9/2026 | 17/9/2026 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure… | |
| Pendiente de análisis | Crítica (9.1) | 0.78% | — | Cisco ISEAI | 16/9/2026 | 17/9/2026 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation… |