Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
2305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Analizada | Alta (7.2) | 0.79% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and… | |
| Analizada | Baja (2.3) | 0.44% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups… | |
| Analizada | Media (5.9) | 0.48% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and… | |
| Analizada | Baja (0.5) | 0.56% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset and Secret references, but framework… | |
| Analizada | Alta (7.5) | 0.62% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject… | |
| Pendiente de análisis | Alta (8.8) | 0.16% | — | Avast Sandbox Minifilter DriverAI | 16/9/2026 | 17/9/2026 | Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened… | |
| Aplazada | Crítica (9.8) | 0.55% | — | UI Unifi Protect AI KEYAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi TalkAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |
| Aplazada | Crítica (9.8) | 1.6% | — | UI Unifi Enterprise Audio Video BridgeAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. | |
| Aplazada | Crítica (9) | 0.37% | — | UI Unifi Connect Display Cast PROAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. | |
| Aplazada | Crítica (10) | 0.80% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | |
| Aplazada | Crítica (9) | 0.51% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9) | 0.39% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.1) | 0.46% | — | UI Unifi Network ApplicationAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. |