Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | — | — | Foreman Remote ExecutionAI | 1/10/2026 | 1/10/2026 | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the… | |
| Aplazada | Sin puntuar | 0.25% | — | Geelen Mcp-remoteAI | 24/9/2026 | 24/9/2026 | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts | |
| Aplazada | Alta (8.8) | 0.53% | — | Geelen MCP RemoteAI | 24/9/2026 | 25/9/2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions | |
| Aplazada | Crítica (9.8) | 0.47% | — | Geelen Mcp-remoteAI | 24/9/2026 | 29/9/2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | |
| Aplazada | Alta (7.5) | 0.47% | — | Geelen Mcp-remoteAI | 24/9/2026 | 24/9/2026 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components | |
| Aplazada | Crítica (9.1) | 0.35% | — | Mcp-remoteAI | 24/9/2026 | 25/9/2026 | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Gnome Remote DesktopAI | 23/9/2026 | 24/9/2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | Theforeman Foreman Remote ExecutionAI | 17/9/2026 | 18/9/2026 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is… | |
| Aplazada | Alta (7.8) | 0.20% | — | Geovision Gv-remote E-mapAI | 17/9/2026 | 18/9/2026 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully… | |
| Aplazada | Alta (8.2) | 0.30% | — | Panasonic Remote I O Coupler UnitAI | 14/9/2026 | 16/9/2026 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | |
| Aplazada | Media (6.9) | 0.34% | — | Contec Remote IO Coupler Unit Cpsn-mcb271AI | 14/9/2026 | 16/9/2026 | Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | |
| Aplazada | Media (4.3) | 0.26% | — | OpenremoteAI | 11/9/2026 | 23/9/2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue. | |
| Analizada | Alta (7.5) | 0.64% | — | Microsoft Remote Desktop Client | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Alta (8.3) | 0.39% | — | OpenremoteAI | 27/8/2026 | 23/9/2026 | OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET… | |
| Aplazada | Alta (8.1) | 0.23% | — | Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI | 26/8/2026 | 26/8/2026 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,… | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | Devolutions Remote Desktop ManagerAIIronvncAI | 24/8/2026 | 28/8/2026 | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication. | |
| Aplazada | Alta (7.3) | 0.12% | — | Remote Utilities HostAI | 21/8/2026 | 26/8/2026 | Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\SYSTEM loads DLLs from this directory. The… | |
| Analizada | Media (5.5) | 0.98% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | |
| Analizada | Alta (7.1) | 0.46% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | |
| Aplazada | Alta (7.1) | 0.22% | — | OpenremoteAI | 13/8/2026 | 23/9/2026 | OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Parameterized Remote TriggerAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |