Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.19%—Recommenders-team RecommendersAI23/9/202623/9/2026
A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The…
AplazadaBaja (3.1)0.56%—Northern.tech Mender ServerAI27/5/202617/6/2026
Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
AplazadaBaja (3.7)0.30%—Northern.tech Mender Enterprise ServerAI27/5/202617/6/2026
Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
AplazadaMedia (5.3)0.18%—Northern.tech Mender ClientAI27/5/202617/6/2026
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
AplazadaCrítica (9.1)0.39%—Northern.tech Mender ServerAI26/6/202517/6/2026
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
AplazadaCrítica (9.1)0.81%—Northern.tech Mender ClientAI21/1/202517/6/2026
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
AplazadaBaja (2.7)0.28%—Northern.tech MenderAI8/11/202417/6/2026
Northern.tech Hosted Mender before 2024.07.11 allows SSRF.
ModificadaMedia (4.3)0.26%—Northern.tech Mender8/11/202417/6/2026
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
AplazadaMedia (6.5)0.39%—Northern.tech MenderAI8/11/202417/6/2026
Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
AplazadaAlta (8.8)0.38%—Northern.tech MenderAI20/6/202417/6/2026
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.
AplazadaMedia (6.5)0.32%—Northern.tech MenderAI20/6/202417/6/2026
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
AplazadaCrítica (9.8)0.58%—Northern.tech Mender EnterpriseAI3/6/202417/6/2026
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
ModificadaMedia (4.3)0.22%—Northern.tech Mender6/7/202217/6/2026
The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network interfaces instead of only the localhost…
ModificadaCrítica (9.8)1.0%—Northern.tech Mender28/4/202217/6/2026
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.
ModificadaAlta (8.8)0.48%—Northern.tech Mender28/4/202217/6/2026
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
ModificadaMedia (6.1)0.85%—EDX Recommender9/8/201917/6/2026
Recommender before 2018-07-18 allows XSS.