Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Hickory-resolverAI | 18/9/2026 | 22/9/2026 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records… | |
| Aplazada | Alta (8.7) | 0.85% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the… | |
| Aplazada | Alta (7.1) | 0.52% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an… | |
| Aplazada | Alta (8.7) | 0.29% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or… | |
| Aplazada | Media (5.1) | 0.26% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unescaped HTML markup, which are interpolated directly into innerHTML during CSV serialization rendering. Attackers can… | |
| Aplazada | Alta (8.7) | 1.2% | — | Resolver PerspectiveAI | 4/8/2026 | 9/9/2026 | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={}… | |
| Aplazada | Alta (8.1) | 0.62% | — | Knot ResolverAI | 25/7/2026 | 30/7/2026 | Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path. | |
| Aplazada | Alta (7.5) | 0.49% | — | FlaresolverrAI | 20/7/2026 | 21/7/2026 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information | |
| Aplazada | Media (4.8) | 0.15% | — | Blackmagicdesign Davinci ResolveAI | 29/5/2025 | 17/6/2026 | Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,… | |
| Aplazada | Alta (8.9) | 0.63% | — | Intlify Message ResolverAIIntlify VUE I18n CoreAIVuejs VUE I18nAI | 7/3/2025 | 17/6/2026 | Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype… | |
| Aplazada | Alta (8.4) | 0.21% | — | Davinci ResolveAI | 28/2/2025 | 17/6/2026 | DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit… | |
| Aplazada | Alta (8.3) | 0.42% | — | Apphp Js-object-resolverAI | 17/6/2024 | 17/6/2026 | apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty. | |
| Modificada | Alta (7.5) | 100% | — | Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+9 | 14/2/2024 | 17/6/2026 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the… | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Sling Servlets Resolver | 6/2/2024 | 17/6/2026 | Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable,… | |
| Modificada | Alta (7.5) | 0.64% | — | NIC Knot Resolver | 22/10/2023 | 17/6/2026 | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers. | |
| Modificada | Alta (7.5) | 0.71% | — | NIC Knot Resolver | 21/2/2023 | 17/6/2026 | Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response. | |
| Modificada | Crítica (9.8) | 0.86% | — | Cisco Openresolve | 2/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The identifier of the patch is 9eba6ba5abd89d0e36a008921eb307fcef8c5311. It is recommended to apply a… | |
| Modificada | Media (6.1) | 0.56% | — | Cisco Openresolve | 2/1/2023 | 17/6/2026 | A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched remotely. The complexity of an attack is rather high. The… | |
| Modificada | Alta (7.5) | 0.24% | — | Go-resolver Project Go-resolver | 28/12/2022 | 17/6/2026 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain. | |
| Modificada | Media (6.5) | 0.23% | — | Go-resolver Project Go-resolver | 28/12/2022 | 17/6/2026 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. The owner name of RRSIG RRs is not validated, permitting an attacker to present the RRSIG for an attacker-controlled domain in a response for any other domain. | |
| Modificada | Alta (7.5) | 1.9% | — | NIC Knot ResolverFedoraproject FedoraDebian Linux | 23/9/2022 | 17/6/2026 | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets. | |
| Modificada | Media (5.3) | 0.74% | — | NIC Knot Resolver | 20/6/2022 | 17/6/2026 | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters. | |
| Modificada | Crítica (9.8) | 18% | — | Blackmagicdesign Davinci Resolve | 22/12/2021 | 17/6/2026 | When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction of the object that owns it, the uninitialized member will be… | |
| Modificada | Crítica (9.8) | 16% | — | Blackmagicdesign Davinci Resolve | 22/12/2021 | 17/6/2026 | When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards… | |
| Modificada | Alta (7.5) | 1.4% | — | NIC Knot Resolver | 25/8/2021 | 17/6/2026 | Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof). |