Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.19% | — | Recommenders-team RecommendersAI | 23/9/2026 | 23/9/2026 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (3.1) | 0.56% | — | Northern.tech Mender ServerAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. | |
| Aplazada | Baja (3.7) | 0.30% | — | Northern.tech Mender Enterprise ServerAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. | |
| Aplazada | Media (5.3) | 0.18% | — | Northern.tech Mender ClientAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. | |
| Aplazada | Crítica (9.1) | 0.39% | — | Northern.tech Mender ServerAI | 26/6/2025 | 17/6/2026 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. | |
| Aplazada | Crítica (9.1) | 0.81% | — | Northern.tech Mender ClientAI | 21/1/2025 | 17/6/2026 | Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. | |
| Aplazada | Baja (2.7) | 0.28% | — | Northern.tech MenderAI | 8/11/2024 | 17/6/2026 | Northern.tech Hosted Mender before 2024.07.11 allows SSRF. | |
| Modificada | Media (4.3) | 0.26% | — | Northern.tech Mender | 8/11/2024 | 17/6/2026 | Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. | |
| Aplazada | Media (6.5) | 0.39% | — | Northern.tech MenderAI | 8/11/2024 | 17/6/2026 | Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF. | |
| Aplazada | Alta (8.8) | 0.38% | — | Northern.tech MenderAI | 20/6/2024 | 17/6/2026 | Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user. | |
| Aplazada | Media (6.5) | 0.32% | — | Northern.tech MenderAI | 20/6/2024 | 17/6/2026 | Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Northern.tech Mender EnterpriseAI | 3/6/2024 | 17/6/2026 | Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication. | |
| Modificada | Media (4.3) | 0.22% | — | Northern.tech Mender | 6/7/2022 | 17/6/2026 | The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network interfaces instead of only the localhost… | |
| Modificada | Crítica (9.8) | 1.0% | — | Northern.tech Mender | 28/4/2022 | 17/6/2026 | The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints. | |
| Modificada | Alta (8.8) | 0.48% | — | Northern.tech Mender | 28/4/2022 | 17/6/2026 | The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. | |
| Modificada | Media (6.1) | 0.85% | — | EDX Recommender | 9/8/2019 | 17/6/2026 | Recommender before 2018-07-18 allows XSS. |