Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.29% | — | Http4s-scala-xmlAI | 24/9/2026 | 30/9/2026 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the… | |
| Pendiente de análisis | Media (6.2) | 0.19% | — | Modelcontextprotocol Kotlin SDKAIKotlinx CoroutinesAIScala-sbt IOAI | 9/9/2026 | 14/9/2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every chunk of bytes received from the stdio transport into… | |
| Analizada | Media (6.5) | 0.31% | — | IBM Reliable Scalable Cluster Technology | 19/8/2026 | 4/9/2026 | IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation. | |
| En análisis | Media (6.8) | 0.08% | — | Intel Xeon Scalable ProcessorsAI | 11/8/2026 | 12/8/2026 | Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially… | |
| Pendiente de análisis | Media (4.3) | 0.09% | — | Intel Xeon 6 Scalable ProcessorsAIIntel TDXAI | 11/8/2026 | 29/9/2026 | Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Scalar AstroAI | 19/5/2026 | 24/7/2026 | scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Scalar AstroAI | 19/5/2026 | 24/7/2026 | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Analizada | Media (6.7) | 0.27% | — | Scala.epfl SBT | 24/3/2026 | 17/6/2026 | sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to these commands without validation. Because… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and… | |
| Aplazada | Media (5.3) | 0.14% | — | Intel Xeon 6 ScalableAI | 12/8/2025 | 17/6/2026 | Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access | |
| Aplazada | Alta (7.3) | 0.18% | — | Intel Xeon 6 ScalableAI | 12/8/2025 | 17/6/2026 | Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Media (6.5) | 0.28% | — | Escalade Glpi PluginAIGlpiAI | 1/7/2025 | 17/6/2026 | Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in version 2.9.11. | |
| Aplazada | Media (5.9) | 0.28% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.52% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Alta (7.1) | 0.44% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.38% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xc316-8AISiemens Scalance Xc324-4AISiemens Scalance Xc332AI+15 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2)… | |
| Modificada | Media (6.7) | 0.11% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve this sensitive information. | |
| Modificada | Alta (8.5) | 0.18% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device. | |
| Modificada | Alta (8.4) | 0.15% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote… | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Analizada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.46% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… |