Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
–

1064 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.21%—Edgeless Systems ContrastAI27/9/202630/9/2026
Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as…
AplazadaAlta (7.6)0.23%—Edgelesssys ContrastAI27/9/202630/9/2026
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying…
AplazadaAlta (8.5)0.19%—Edgeless Systems ContrastAI27/9/202630/9/2026
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes…
AplazadaMedia (5.1)0.16%—Edgeless Systems ContrastAI27/9/202630/9/2026
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when…
AplazadaAlta (8.5)0.21%—Edgelesssys ContrastAI27/9/202628/9/2026
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list…
AplazadaAlta (8.4)0.24%—Akia Keyless EntryAI25/9/202625/9/2026
Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other…
Pendiente de análisisAlta (8.6)2.1%—FrictionlessAI23/9/202628/9/2026
Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values…
Pendiente de análisisMedia (5.3)0.61%—Beautiful SoupAIFacelessuser Soup SieveAI17/9/202630/9/2026
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled…
Pendiente de análisisMedia (5.3)0.61%—Beautiful SoupAIFacelessuser Soup SieveAI17/9/202623/9/2026
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every…
AplazadaCrítica (9.8)0.61%—Headless Single Sign ONAI17/9/202617/9/2026
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
AplazadaAlta (7.1)0.45%—BrowserlessAI16/9/202622/9/2026
browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the…
ModificadaMedia (6.5)0.81%—Apache-airflow-providers-akeyless16/9/202617/9/2026
Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,…
AplazadaAlta (8.6)0.63%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
AplazadaMedia (4.8)0.24%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaAlta (8.7)1.9%—Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI14/9/202616/9/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (4.8)0.24%—Pc-helper Wireless IO Dio-0404ry-lwfAIPc-helper Wireless IO Dio-0404ry-lwf-usAI14/9/202616/9/2026
Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (5.5)0.70%—Evanchiu Serverless-todoAI13/9/202615/9/2026
A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and…
AplazadaAlta (8.1)0.38%—UDX Wp-statelessAI10/9/202610/9/2026
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Pendiente de análisisMedia (5.3)0.16%—Sierrawireless Hl78xxAI10/9/202610/9/2026
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first…
AplazadaMedia (5.1)0.40%—Elenavanengelenmaslova Mocknest-serverlessAI8/9/202623/9/2026
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is…
Pendiente de análisisMedia (6.4)0.40%—VenuelessAI31/8/20263/9/2026
The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.
Pendiente de análisisMedia (6.4)0.29%—Sierrawireless Hl7800AI18/8/202626/8/2026
The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) parses AT responses with roughly twenty handlers that call net_buf_linearize(value, sizeof(value), *buf, 0, len) into a 128-byte stack buffer and then write…
AplazadaCrítica (9.8)0.56%—Headless Single Sign ONAI13/8/202614/8/2026
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
AplazadaCrítica (9.8)0.34%—Headless Single Sign ONAI13/8/202614/8/2026
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.