Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.09% | — | Mitel Linux Virtual MachineAI | 5/10/2026 | 6/10/2026 | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object… | |
| Aplazada | Crítica (9) | 0.20% | — | Soft MachineAI | 30/9/2026 | 2/10/2026 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the… | |
| Aplazada | Alta (8.3) | 0.27% | — | Soft MachineAI | 30/9/2026 | 30/9/2026 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Cockpit-machinesAI | 18/9/2026 | 22/9/2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the… | |
| Pendiente de análisis | Media (5) | 0.15% | — | Cockpit-machinesAI | 18/9/2026 | 18/9/2026 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON… | |
| Pendiente de análisis | Media (5) | 0.10% | — | Cockpit-project Cockpit MachinesAI | 18/9/2026 | 22/9/2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation… | |
| Analizada | Alta (7.5) | 0.54% | — | Microsoft Azure Machine Learning | 17/9/2026 | 25/9/2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9.1) | 0.23% | — | TMT Machine Industry AND Trade Ltd. CO Talassoft Industrial Management SoftwareAI | 1/9/2026 | 1/9/2026 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Aplazada | Alta (7.1) | 0.12% | — | TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI | 1/9/2026 | 1/9/2026 | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Aplazada | Alta (7.5) | 0.40% | — | TMT Machine Industry AND Trade LTD CO Talassoft Industrial Management SoftwareAI | 1/9/2026 | 1/9/2026 | Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16. | |
| Aplazada | Alta (8.8) | 0.29% | — | TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI | 1/9/2026 | 1/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. | |
| Pendiente de análisis | Alta (8.6) | 0.36% | — | Simplemachines ForumAI | 26/8/2026 | 24/9/2026 | Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between… | |
| Analizada | Alta (8.5) | 0.56% | — | Microsoft Azure Virtual Machines | 20/8/2026 | 26/8/2026 | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.8) | 1.2% | — | NomachineAI | 20/8/2026 | 1/9/2026 | NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000… | |
| Analizada | Media (6.3) | 0.32% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence:… | |
| Analizada | Alta (8.3) | 0.59% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying service to legitimate payers once it is empty. MPP.Methods.Tempo.FeePayerPolicy enforces its ceilings (max_gas, max_fee_per_gas,… | |
| Analizada | Alta (8.2) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithMemo to the specific challenge under verification through an attribution nonce… | |
| Analizada | Alta (8.7) | 0.60% | — | Zenhive Machine Payments Protocol | 19/8/2026 | 10/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and matches a transfer purely on token, to and amount (ERC-20) or to and value (native).… | |
| Aplazada | Alta (7.5) | 0.70% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and allows those goroutines to concurrently write to the shared ctx.files, ctx.diskToOriginal, and… | |
| Aplazada | Alta (7.5) | 0.37% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix, Teredo, and other transition prefixes that… | |
| Aplazada | Alta (8.8) | 0.50% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sanitization. The… | |
| Analizada | Media (5.4) | 0.16% | — | Intel Hardware-aware-automated-machine-learning | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Pendiente de análisis | Media (4.7) | 0.11% | — | Systemd-machinedAI | 10/8/2026 | 1/9/2026 | When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged… |