Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.30%—Nvidia NvosAI18/8/202620/8/2026
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not…
AnalizadaAlta (8.8)0.36%—Nvidia Cumulus LinuxNvidia Nvos24/2/202617/6/2026
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
AnalizadaAlta (8.8)0.80%—Nvidia Cumulus LinuxNvidia Nvos24/2/202617/6/2026
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
AnalizadaAlta (8.8)0.53%—Nvidia Cumulus LinuxNvidia Nvos24/2/202617/6/2026
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.
AplazadaMedia (5.5)0.17%—Nvidia Cumulus LinuxAINvidia NvosAI4/9/202517/6/2026
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.
ModificadaMedia (5.4)0.83%—Convos4/1/202217/6/2026
Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS…
ModificadaMedia (5.4)0.93%—Convos4/1/202217/6/2026
Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an…
ModificadaMedia (5.4)0.73%—Convos17/12/202117/6/2026
A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.
ModificadaMedia (5.3)1.1%—Convos18/6/202017/6/2026
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.