Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.35% | — | Cohere North AIAI | 26/8/2026 | 3/9/2026 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | |
| Aplazada | Alta (7.5) | 0.26% | — | Cohere North AIAI | 26/8/2026 | 3/9/2026 | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | |
| Aplazada | Crítica (9.8) | 0.28% | — | Cohere North AIAI | 26/8/2026 | 3/9/2026 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests. | |
| Aplazada | Alta (7.5) | 0.21% | — | Cohere North AIAI | 26/8/2026 | 3/9/2026 | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint | |
| Aplazada | Media (6.3) | 0.13% | — | Northbridge LuminalshineAI | 13/8/2026 | 9/9/2026 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and is created by the `SYSTEM` service. Under Windows' default… | |
| Pendiente de análisis | Media (6.1) | 0.28% | — | Northern.tech Cfengine EnterpriseAI | 2/6/2026 | 22/7/2026 | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. | |
| Aplazada | Baja (3.1) | 0.56% | — | Northern.tech Mender ServerAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. | |
| Aplazada | Baja (3.7) | 0.30% | — | Northern.tech Mender Enterprise ServerAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. | |
| Aplazada | Media (5.3) | 0.18% | — | Northern.tech Mender ClientAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. | |
| Analizada | Alta (7.3) | 0.92% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. | |
| Analizada | Media (5.3) | 0.21% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. | |
| Analizada | Media (6.1) | 0.17% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. | |
| Aplazada | Media (6.5) | 0.22% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XSS.This issue affects WP Custom Admin Interface: from n/a through <= 7.42. | |
| Aplazada | Media (4.3) | 0.19% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41. | |
| Aplazada | Alta (8.1) | 0.63% | — | Fuelthemes NorthAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North north-wp allows PHP Local File Inclusion.This issue affects North: from n/a through <= 5.7.5. | |
| Aplazada | Alta (8.8) | 0.47% | — | Fuelthemes NorthAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in fuelthemes North north-wp allows Object Injection.This issue affects North: from n/a through <= 5.7.5. | |
| Aplazada | Media (4.3) | 0.24% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40. | |
| Aplazada | Alta (7.5) | 0.46% | — | Fuelthemes North PluginAI | 9/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required Plugin north-plugin allows PHP Local File Inclusion.This issue affects North - Required Plugin: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.19% | — | Espec North America WEB ControllerAI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout. | |
| Aplazada | Media (4.3) | 0.19% | — | Espec North America WEB Controller 3AI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Espec North America WEB ControllerAI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI. | |
| Aplazada | Media (5.3) | 0.29% | — | Dromara NorthstarAI | 14/7/2025 | 17/6/2026 | A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument… | |
| Analizada | Baja (2.1) | 0.82% | — | Blackvuenorthamerica Blackvue Dr590x Firmware | 6/7/2025 | 17/6/2026 | A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local… | |
| Analizada | Baja (2.1) | 0.89% | — | Blackvuenorthamerica Blackvue Dr590x Firmware | 6/7/2025 | 17/6/2026 | A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within the local network.… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Northern.tech Mender ServerAI | 26/6/2025 | 17/6/2026 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. |