Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.53% | — | Lutece CoreAI | 1/9/2026 | 1/9/2026 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to be executed from… | |
| Analizada | Alta (8.7) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. | |
| Analizada | Media (6.9) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure… | |
| Analizada | Media (6) | 0.37% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service. | |
| Analizada | Media (5.1) | 0.37% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher. | |
| Analizada | Media (6.9) | 0.35% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |
| Analizada | Alta (8.7) | 0.40% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |
| Analizada | Media (6.9) | 0.35% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |
| Modificada | Baja (2.3) | 0.38% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |
| Modificada | Media (6.1) | 0.43% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. | |
| Modificada | Baja (2.1) | 0.27% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak. | |
| Modificada | Baja (2.1) | 0.32% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |
| Modificada | Baja (2.1) | 0.32% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client | |
| Modificada | Media (6.7) | 0.10% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control. | |
| Modificada | Alta (8.5) | 0.14% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location. | |
| Modificada | Alta (7.1) | 0.37% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |
| Aplazada | Alta (8.6) | 0.53% | — | LuteAIB3log SiyuanAI | 9/7/2026 | 10/7/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in… | |
| Aplazada | Alta (8.7) | 0.44% | — | LuteAIB3log SiyuanAI | 24/6/2026 | 25/6/2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron client's permissive security configuration, an attacker can include a malicious <iframe> in a Bazaar package README that executes arbitrary commands… | |
| Aplazada | Media (5.1) | 0.33% | — | Evoluted PHP Directory Listing ScriptAI | 9/6/2026 | 23/7/2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary… | |
| Analizada | Media (6.8) | 0.13% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. | |
| Analizada | Alta (7.1) | 0.42% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service | |
| Analizada | Media (6.8) | 0.14% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. | |
| Analizada | Media (5.9) | 0.13% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. | |
| Analizada | Alta (8.5) | 0.15% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system. | |
| Analizada | Baja (2.3) | 0.26% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service. |