Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

2338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.29%—Office Powerpoint MCP ServerAI1/10/20262/10/2026
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or…
Pendiente de análisisMedia (6)0.31%—Amazon Powertools FOR AWS Lambda PythonAI1/10/20262/10/2026
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
AplazadaMedia (5.5)0.45%—Netcore Power13AI28/9/20261/10/2026
A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was…
AplazadaMedia (6.8)0.24%—Blubrry PowerpressAI27/9/202628/9/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AnalizadaAlta (7.1)0.18%—IBM Power System E1080 (9080-hex) FirmwareIBM Power System E1180 (9080-heu) FirmwareIBM Power System S922 (9009-22g) FirmwareIBM Power System H922 (9223-22s) Firmware+525/9/202630/9/2026
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to…
Pendiente de análisisBaja (2.4)0.14%—Tohoku Electric Power Yorisou E NETAI25/9/202629/9/2026
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
AnalizadaBaja (3.2)0.11%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1524/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging…
AnalizadaMedia (4.3)0.18%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2224/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
AnalizadaBaja (3.4)0.11%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+1324/9/202630/9/2026
IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in…
AnalizadaBaja (3.4)0.13%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2224/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a…
En análisisMedia (4.4)0.10%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2224/9/202629/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware…
AnalizadaMedia (5.1)0.10%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2224/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker with root access to a partition can maliciously alter partition nvram, causing the…
AnalizadaMedia (5.1)0.10%—IBM Power System S1122 (9824-22a) FirmwareIBM Power System S1124 (9824-42a) FirmwareIBM Power System S1122s (9824-22b) FirmwareIBM Power System S1114 (9824-41b) Firmware+2224/9/202630/9/2026
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrator-level (root) access to a logical partition can send a specially crafted request…
Pendiente de análisisAlta (7.8)0.16%—Dell Command Powershell ProviderAI21/9/202624/9/2026
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
AplazadaMedia (5.3)0.62%—Wordlift AI Powered SEO SchemaAI19/9/202621/9/2026
The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /wordlift/v1/jsonld/ routes (jsonld/{id}, jsonld/http/{item_id},…
Pendiente de análisisMedia (6.5)0.37%—Devolutions Powershell UniversalAI15/9/202616/9/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
AnalizadaMedia (6.7)0.53%—Dell Powerscale Onefs9/9/202616/9/2026
Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting…
AnalizadaBaja (3.5)0.18%—Dell Powerscale Onefs9/9/202616/9/2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs.
AnalizadaMedia (5.4)0.39%—Dell Powerscale Onefs9/9/202616/9/2026
Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (6.5)0.97%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.