Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
1064 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.21% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as… | |
| Aplazada | Alta (7.6) | 0.23% | — | Edgelesssys ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying… | |
| Aplazada | Alta (8.5) | 0.19% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes… | |
| Aplazada | Media (5.1) | 0.16% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when… | |
| Aplazada | Alta (8.5) | 0.21% | — | Edgelesssys ContrastAI | 27/9/2026 | 28/9/2026 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list… | |
| Aplazada | Alta (8.4) | 0.24% | — | Akia Keyless EntryAI | 25/9/2026 | 25/9/2026 | Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other… | |
| Pendiente de análisis | Alta (8.6) | 2.1% | — | FrictionlessAI | 23/9/2026 | 28/9/2026 | Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values… | |
| Pendiente de análisis | Media (5.3) | 0.61% | — | Beautiful SoupAIFacelessuser Soup SieveAI | 17/9/2026 | 30/9/2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled… | |
| Pendiente de análisis | Media (5.3) | 0.61% | — | Beautiful SoupAIFacelessuser Soup SieveAI | 17/9/2026 | 23/9/2026 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Headless Single Sign ONAI | 17/9/2026 | 17/9/2026 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Aplazada | Alta (7.1) | 0.45% | — | BrowserlessAI | 16/9/2026 | 22/9/2026 | browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the… | |
| Modificada | Media (6.5) | 0.81% | — | Apache-airflow-providers-akeyless | 16/9/2026 | 17/9/2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,… | |
| Aplazada | Alta (8.6) | 0.63% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (5.5) | 0.70% | — | Evanchiu Serverless-todoAI | 13/9/2026 | 15/9/2026 | A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and… | |
| Aplazada | Alta (8.1) | 0.38% | — | UDX Wp-statelessAI | 10/9/2026 | 10/9/2026 | Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | |
| Pendiente de análisis | Media (5.3) | 0.16% | — | Sierrawireless Hl78xxAI | 10/9/2026 | 10/9/2026 | The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first… | |
| Aplazada | Media (5.1) | 0.40% | — | Elenavanengelenmaslova Mocknest-serverlessAI | 8/9/2026 | 23/9/2026 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is… | |
| Pendiente de análisis | Media (6.4) | 0.40% | — | VenuelessAI | 31/8/2026 | 3/9/2026 | The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set. | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Sierrawireless Hl7800AI | 18/8/2026 | 26/8/2026 | The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) parses AT responses with roughly twenty handlers that call net_buf_linearize(value, sizeof(value), *buf, 0, len) into a 128-byte stack buffer and then write… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Headless Single Sign ONAI | 13/8/2026 | 14/8/2026 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Headless Single Sign ONAI | 13/8/2026 | 14/8/2026 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. |