Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.35% | — | Pocketmine-mpAIJsonmapperAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server. | |
| Aplazada | Alta (8.7) | 0.46% | — | ReconmapAI | 21/8/2026 | 24/9/2026 | Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in apps/api/app/Controllers/ReportsController.cs carries [AllowAnonymous]… | |
| Pendiente de análisis | Media (6.6) | 0.43% | — | Splunk Nmap ScannerAI | 19/8/2026 | 20/8/2026 | In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting… | |
| Pendiente de análisis | Media (6.9) | 0.50% | — | NmapAI | 11/8/2026 | 24/9/2026 | Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an… | |
| Pendiente de análisis | Media (4.8) | 0.13% | — | Nmap NpcapAI | 11/8/2026 | 28/8/2026 | The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic… | |
| Analizada | Media (6.9) | 1.5% | — | Nmap | 28/6/2026 | 30/6/2026 | Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response… | |
| Aplazada | Media (6.9) | 0.12% | — | NmapAIZenmapAI | 26/4/2026 | 17/6/2026 | Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the… | |
| Analizada | Media (5.3) | 4.5% | — | Phialsbasement MCP Nmap Server | 3/3/2026 | 17/6/2026 | A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from… | |
| Aplazada | Crítica (10) | 1.9% | — | Snort ReportAINmapAINbtscanAI | 13/8/2025 | 16/6/2026 | Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result… | |
| Aplazada | Media (6.6) | 0.28% | — | Nmap ImporterAIMicrosoft Windows RegistryAI | 8/4/2024 | 17/6/2026 | The NMAP Importer service may expose data store credentials to authorized users of the Windows Registry. | |
| Modificada | Crítica (9.8) | 5.5% | — | Python-libnmap Project Python-libnmap | 4/5/2022 | 17/6/2026 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted… | |
| Modificada | Alta (7.5) | 3.2% | — | Nmap | 29/8/2019 | 17/6/2026 | nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse. | |
| Modificada | Alta (7.5) | 1.6% | — | Libnmap | 15/7/2019 | 17/6/2026 | libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload. | |
| Modificada | Media (5.3) | 1.6% | — | Dynmap Project Dynmap | 28/5/2019 | 17/6/2026 | In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting. | |
| Modificada | Alta (7.8) | 0.71% | — | Nmap Npcap | 24/4/2019 | 17/6/2026 | An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privileges. | |
| Modificada | Crítica (9.8) | 3.9% | — | Libnmap Project Libnmap | 30/10/2018 | 17/6/2026 | A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options. | |
| Modificada | Crítica (9.8) | 1.6% | — | Nmap4j Project Nmap4j | 19/9/2018 | 17/6/2026 | nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call. | |
| Modificada | Alta (7.5) | 6.1% | — | Nmap | 8/8/2018 | 17/6/2026 | Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service. | |
| Modificada | Media (5.7) | 1.0% | — | Nmap | 18/4/2018 | 17/6/2026 | nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site.… | |
| Modificada | Media (6.8) | 7.2% | — | NmapOpensuse | 26/10/2013 | 16/6/2026 | The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences. | |
| Modificada | Media (6) | 2.0% | — | Baconmap | 27/4/2011 | 16/6/2026 | Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Baconmap | 27/4/2011 | 16/6/2026 | SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | |
| Modificada | Alta (8.3) | 1.9% | — | HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+14 | 18/10/2010 | 16/6/2026 | Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors. |