Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
1458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Geminilabs Site ReviewsAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | |
| Aplazada | Alta (7.8) | 0.15% | — | Reachy Mini ISOAI | 30/9/2026 | 30/9/2026 | Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Geminilabs Site ReviewsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Minimum AND Maximum Quantity FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Tibco AdministratorAI | 29/9/2026 | 30/9/2026 | Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | |
| Aplazada | Media (5.1) | 0.19% | — | Amirsanni Mini Inventory AND Sales Management SystemAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to… | |
| Aplazada | Baja (2.1) | 0.19% | — | Amirsanni Mini Inventory AND Sales Management SystemAI | 27/9/2026 | 28/9/2026 | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Miniorange OTP Login Verification SMS NotificationsAI | 26/9/2026 | 28/9/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | MinioAIPgsty SiloAI | 25/9/2026 | 30/9/2026 | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives… | |
| Aplazada | Sin puntuar | 0.15% | — | Mini-xmlAI | 24/9/2026 | 24/9/2026 | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control to the cleanup path. These orphaned nodes are not released, resulting in a… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Minimp3AI | 24/9/2026 | 29/9/2026 | minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field. | |
| Aplazada | Media (6.3) | 0.16% | — | Pollen Robotics Reachy MiniAIBluezAI | 23/9/2026 | 23/9/2026 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else's successful authentication. The authenticated state is kept in a single shared flag on the service… | |
| Aplazada | Alta (8.8) | 0.17% | — | Pollen Robotics Reachy MiniAIHuggingface SpacesAI | 23/9/2026 | 23/9/2026 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's only dependency is Depends(get_app_manager), which just hands back the manager object from application state, so… | |
| En análisis | Media (6.8) | 0.13% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| En análisis | Alta (7.4) | 0.37% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 19/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| En análisis | Alta (7.2) | 0.46% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Alta (7.3) | 0.14% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| En análisis | Media (6.5) | 0.44% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| En análisis | Media (6.4) | 0.23% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 19/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| En análisis | Alta (8.1) | 0.38% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. | |
| En análisis | Media (5.4) | 0.21% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| En análisis | Alta (7.5) | 0.53% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| En análisis | Alta (7.2) | 0.62% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| En análisis | Media (5.8) | 0.23% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | |
| En análisis | Alta (8.1) | 0.38% | — | Dell Openmanage Server AdministratorAI | 17/9/2026 | 18/9/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |