Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.33%—OpenobserveAI24/9/20265/10/2026
OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so…
AplazadaAlta (7.1)0.46%—SecobserveAI16/9/202624/9/2026
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service…
AplazadaAlta (7.5)0.52%—Observeinc ObserveAI15/6/202617/6/2026
An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.
AplazadaMedia (6.9)0.12%—Observerip Scan ToolAI26/4/202617/6/2026
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation to cause an…
Pendiente de análisisCrítica (9.8)0.92%—Talend JobserverAITalend RuntimeAI14/4/202617/6/2026
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by requiring TLS client authentication for the…
AnalizadaAlta (7.7)0.36%—Openobserve7/4/202624/7/2026
OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block IPv6 addresses because Rust's url crate returns them with surrounding brackets (e.g. "[::1]" not "::1"). An authenticated attacker can…
AplazadaAlta (8.4)0.27%—OpenobserveAI29/11/202517/6/2026
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid…
AplazadaBaja (3.5)0.18%—OpenobserveAI13/11/202517/6/2026
OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML in the name, the markup is rendered inside the invitation email. This indicates that user-controlled input is inserted into the email template without proper HTML escaping.…
AplazadaAlta (8.7)0.51%—OpenobserveAI16/1/202517/6/2026
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended privilege hierarchy, enabling a non-root user to remove the highest-privileged…
ModificadaMedia (6.1)0.36%—Openobserve25/7/202417/6/2026
OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of `openobserve/web/src/views/MemberSubscription.vue`. Version 0.10.0 sanitizes incoming html.
ModificadaMedia (5.4)0.53%—Openobserve25/7/202417/6/2026
The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It has been noted that…
ModificadaMedia (6.5)0.49%—Openobserve8/2/202417/6/2026
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user within an organization to remove any other…
ModificadaAlta (8.8)0.72%—Openobserve8/2/202417/6/2026
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to add new users with elevated privileges,…
ModificadaAlta (7.5)1.1%—Auto-maskin RP 210e FirmwareAuto-maskin DCU 210e FirmwareAuto-maskin Marine PRO Observer23/3/202017/6/2026
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
ModificadaCrítica (9.1)1.1%—Auto-maskin Rp210e FirmwareAuto-maskin DCU 210 FirmwareAuto-maskin Marine PRO Observer23/3/202017/6/2026
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
ModificadaAlta (8.8)0.88%—Auto-maskin RP 210e FirmwareAuto-maskin DCU 210e FirmwareAuto-maskin Marine PRO Observer8/10/201817/6/2026
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and upload executable code via file upload for…
ModificadaMedia (5.9)0.87%—Auto-maskin RP 210e FirmwareAuto-maskin DCU 210e FirmwareAuto-maskin Marine PRO Observer8/10/201817/6/2026
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The devices transmit process control information via unencrypted Modbus communications. Impact: An attacker can exploit…
ModificadaMedia (4.3)1.4%—Hitachi JP1 Integrated Management Service SupportHitachi Jp1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/automatic JOB Management System 2-viewHitachi JOB Management Partner 1/integrated Management-view+1021/4/201016/6/2026
Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."
ModificadaAlta (10)14%—Project-observer Observer29/9/200816/6/2026
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.
ModificadaMedia (5)1.6%—Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+527/4/200616/6/2026
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.