Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.30% | — | Nvidia NvosAI | 18/8/2026 | 20/8/2026 | NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not… | |
| Analizada | Alta (8.8) | 0.36% | — | Nvidia Cumulus LinuxNvidia Nvos | 24/2/2026 | 17/6/2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Analizada | Alta (8.8) | 0.80% | — | Nvidia Cumulus LinuxNvidia Nvos | 24/2/2026 | 17/6/2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Analizada | Alta (8.8) | 0.53% | — | Nvidia Cumulus LinuxNvidia Nvos | 24/2/2026 | 17/6/2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Media (5.5) | 0.17% | — | Nvidia Cumulus LinuxAINvidia NvosAI | 4/9/2025 | 17/6/2026 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users. | |
| Modificada | Media (5.4) | 0.83% | — | Convos | 4/1/2022 | 17/6/2026 | Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS. Also, after uploading a file the XSS… | |
| Modificada | Media (5.4) | 0.93% | — | Convos | 4/1/2022 | 17/6/2026 | Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does not exist. Through this vulnerability, an… | |
| Modificada | Media (5.4) | 0.73% | — | Convos | 17/12/2021 | 17/6/2026 | A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32. | |
| Modificada | Media (5.3) | 1.1% | — | Convos | 18/6/2020 | 17/6/2026 | Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations. |