Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
837 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.27% | — | 10up Safe SVGAI | 30/9/2026 | 30/9/2026 | Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | 10up Safe SVGAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | |
| Aplazada | Baja (3.4) | 0.18% | — | Safe Redirect ManagerAI | 30/9/2026 | 30/9/2026 | The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | |
| Aplazada | Crítica (9.2) | 0.71% | — | SafelineAI | 16/9/2026 | 23/9/2026 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain… | |
| Pendiente de análisis | Crítica (9) | 0.33% | — | Slab SafeurlAI | 15/9/2026 | 21/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address it approved, so the HTTP clients the library ships receive the original hostname… | |
| Pendiente de análisis | Crítica (9) | 0.48% | — | Slab SafeurlAI | 15/9/2026 | 21/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing,… | |
| Aplazada | Media (6.3) | 0.52% | — | SafeurlAI | 14/9/2026 | 30/9/2026 | safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIPv6(true), an attacker-controlled destination in one of these ranges is not… | |
| Pendiente de análisis | Media (4) | 0.45% | — | Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI | 10/9/2026 | 11/9/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Crítica (9.1) | 1.2% | — | RapisafeAI | 15/8/2026 | 20/8/2026 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (4.7) | 0.42% | — | Probo SaferedirectAIProbodAI | 13/8/2026 | 18/9/2026 | Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version 0.19.3.1, the… | |
| Aplazada | Alta (7.5) | 0.50% | — | Admin Safety GuardAI | 8/8/2026 | 26/8/2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Safetipin Android ApplicationAI | 5/8/2026 | 1/10/2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | |
| Aplazada | Media (5.5) | 0.41% | — | Esafenet CDGAI | 5/8/2026 | 12/8/2026 | A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was… | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 30/7/2026 | 31/8/2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a… | |
| Pendiente de análisis | Media (5.9) | 0.40% | — | Trezor Safe 3AITrezor Safe 5AITrezor Safe 7AI | 21/7/2026 | 30/7/2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then… | |
| Aplazada | Baja (1.9) | 0.32% | — | Princezuda SafestclawAI | 18/7/2026 | 22/7/2026 | A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist. An attack has to be approached locally. The… | |
| Aplazada | Media (6.7) | 0.15% | — | Txone Networks SafeportagentAITxone Networks StellarprotectAI | 17/7/2026 | 27/7/2026 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the… | |
| Pendiente de análisis | Alta (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 16/7/2026 | 17/7/2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. | |
| Aplazada | Alta (7.7) | 0.38% | — | PretixAIPretix MollieAIPretix OppwaAIPretix BitpayAI+5 | 1/7/2026 | 2/7/2026 | We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and… | |
| Pendiente de análisis | Alta (7.5) | 0.41% | — | Safetica Endpoint ClientAI | 26/6/2026 | 26/6/2026 | Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes. | |
| Aplazada | Alta (8.7) | 0.33% | — | Safeline SL6AISafeline Sl6+AI | 22/6/2026 | 30/9/2026 | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an… | |
| Aplazada | Media (6.9) | 0.43% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path generation for uploaded files, profile pictures, and settings. An authenticated… | |
| Aplazada | Media (6.8) | 0.14% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to the application files can reverse engineer the DLL and recover the hard-coded cryptographic key. This key can be used to… |