Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Sharp Multifunction PrinterAIToshibatec Multifunction PrinterAI | 1/10/2026 | 2/10/2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as… | |
| Pendiente de análisis | Media (4.7) | 0.12% | — | Toshiba File ParserAI | 29/9/2026 | 29/9/2026 | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (8.6) | 0.29% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Photoshop | 8/9/2026 | 11/9/2026 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Photoshop | 8/9/2026 | 14/9/2026 | Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5) | 0.19% | — | Adobe Photoshop Mobile | 8/9/2026 | 9/9/2026 | Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions.… | |
| Analizada | Alta (7.4) | 0.21% | — | Adobe Photoshop Mobile | 8/9/2026 | 9/9/2026 | Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a… | |
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Cloudfoundry Bosh CLIAI | 21/8/2026 | 28/8/2026 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in… | |
| Pendiente de análisis | Baja (2.1) | 0.19% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1,… | |
| Aplazada | Media (5.9) | 0.26% | — | GoshsAI | 18/8/2026 | 18/9/2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the… | |
| Aplazada | Alta (8.1) | 0.38% | — | GoshsAI | 18/8/2026 | 18/9/2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no… | |
| Aplazada | Media (6.1) | 0.18% | — | OH MY PoshAI | 13/8/2026 | 9/9/2026 | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Subject, Commit.Author.Name, Commit.Author.Email, and RawUpstreamURL, without… | |
| Aplazada | Alta (7.8) | 0.21% | — | OH MY PoshAI | 13/8/2026 | 9/9/2026 | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go… | |
| Pendiente de análisis | Media (4.2) | 0.21% | — | Cloudfoundry Bosh AgentAI | 6/8/2026 | 18/8/2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0… | |
| Aplazada | Baja (2.1) | 0.54% | — | Yushine InnoshopAI | 5/8/2026 | 12/8/2026 | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been… | |
| Pendiente de análisis | Media (6.9) | 0.43% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user… | |
| Pendiente de análisis | Baja (2.4) | 0.22% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. |