Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.2)0.25%—Kiteworks Advanced FormsAI30/9/20261/10/2026
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
Pendiente de análisisCrítica (9.4)0.24%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is…
Pendiente de análisisCrítica (9.3)0.29%—Kiteworks CoreAI30/9/20261/10/2026
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative…
Pendiente de análisisMedia (5.3)0.36%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
Pendiente de análisisAlta (7.2)0.39%—Accellion KiteworksAI30/9/20261/10/2026
A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification…
Pendiente de análisisMedia (6.7)0.10%—Kiteworks CoreAI30/9/20261/10/2026
Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch…
Pendiente de análisisMedia (6.5)0.26%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither…
Pendiente de análisisMedia (6.6)0.41%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and…
Pendiente de análisisMedia (5.4)0.21%—Kiteworks CoreAI30/9/20261/10/2026
Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were…
Pendiente de análisisMedia (6.6)0.40%—Kiteworks CoreAI30/9/20261/10/2026
An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service…
Pendiente de análisisAlta (7.2)0.34%—Kiteworks CoreAI30/9/20261/10/2026
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator…
Pendiente de análisisAlta (7.2)0.39%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code…
Pendiente de análisisAlta (7.2)0.39%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
Pendiente de análisisAlta (7.2)0.27%—Kiteworks CoreAI30/9/20261/10/2026
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
Pendiente de análisisAlta (7.5)0.21%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to…
Pendiente de análisisAlta (7)0.19%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including…
Pendiente de análisisAlta (8.1)0.21%—Kiteworks CoreAI30/9/20261/10/2026
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have…
Pendiente de análisisAlta (8.8)0.13%—Accellion KiteworksAI30/9/20261/10/2026
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in…
Pendiente de análisisMedia (6.5)0.21%—Accellion KiteworksAI30/9/20261/10/2026
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial…
Pendiente de análisisMedia (4.3)0.16%—Accellion KiteworksAI30/9/20261/10/2026
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
Pendiente de análisisAlta (8.6)0.29%—Accellion KiteworksAI30/9/20261/10/2026
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's…
Pendiente de análisisAlta (8.8)0.14%—Accellion KiteworksAI30/9/20261/10/2026
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster…
Pendiente de análisisAlta (7.8)0.13%—Accellion KiteworksAI30/9/20261/10/2026
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
Pendiente de análisisAlta (7.2)0.64%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
Pendiente de análisisCrítica (9.8)0.33%—Kiteworks CoreAI30/9/20261/10/2026
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user,…