Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.35%—Cohere North AIAI26/8/20263/9/2026
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
AplazadaAlta (7.5)0.26%—Cohere North AIAI26/8/20263/9/2026
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
AplazadaCrítica (9.8)0.28%—Cohere North AIAI26/8/20263/9/2026
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
AplazadaAlta (7.5)0.21%—Cohere North AIAI26/8/20263/9/2026
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint
AplazadaMedia (6.3)0.13%—Northbridge LuminalshineAI13/8/20269/9/2026
NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and is created by the `SYSTEM` service. Under Windows' default…
Pendiente de análisisMedia (6.1)0.28%—Northern.tech Cfengine EnterpriseAI2/6/202622/7/2026
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
AplazadaBaja (3.1)0.56%—Northern.tech Mender ServerAI27/5/202617/6/2026
Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
AplazadaBaja (3.7)0.30%—Northern.tech Mender Enterprise ServerAI27/5/202617/6/2026
Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
AplazadaMedia (5.3)0.18%—Northern.tech Mender ClientAI27/5/202617/6/2026
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
AnalizadaAlta (7.3)0.92%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
AnalizadaMedia (5.3)0.21%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
AnalizadaMedia (6.1)0.17%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
AplazadaMedia (6.5)0.22%—Northernbeacheswebsites WP Custom Admin InterfaceAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XSS.This issue affects WP Custom Admin Interface: from n/a through <= 7.42.
AplazadaMedia (4.3)0.19%—Northernbeacheswebsites WP Custom Admin InterfaceAI3/2/202617/6/2026
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41.
AplazadaAlta (8.1)0.63%—Fuelthemes NorthAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North north-wp allows PHP Local File Inclusion.This issue affects North: from n/a through <= 5.7.5.
AplazadaAlta (8.8)0.47%—Fuelthemes NorthAI22/1/202617/6/2026
Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.7.5.
AplazadaMedia (4.3)0.24%—Northernbeacheswebsites WP Custom Admin InterfaceAI31/12/202523/9/2026
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40.
AplazadaAlta (7.5)0.46%—Fuelthemes North PluginAI9/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2.
AplazadaMedia (4.3)0.19%—Espec North America WEB ControllerAI14/8/202517/6/2026
In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
AplazadaMedia (4.3)0.19%—Espec North America WEB Controller 3AI14/8/202517/6/2026
In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.
AplazadaCrítica (9.8)0.43%—Espec North America WEB ControllerAI14/8/202517/6/2026
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.
AplazadaMedia (5.3)0.29%—Dromara NorthstarAI14/7/202517/6/2026
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument…
AnalizadaBaja (2.1)0.82%—Blackvuenorthamerica Blackvue Dr590x Firmware6/7/202517/6/2026
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local…
AnalizadaBaja (2.1)0.89%—Blackvuenorthamerica Blackvue Dr590x Firmware6/7/202517/6/2026
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within the local network.…
AplazadaCrítica (9.1)0.39%—Northern.tech Mender ServerAI26/6/202517/6/2026
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.