Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
701 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Theeventscalendar THE Events CalendarAI | 2/10/2026 | 2/10/2026 | The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Media (5.4) | 0.20% | — | Theeventscalendar THE Events CalendarAI | 30/9/2026 | 30/9/2026 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | |
| Pendiente de análisis | Media (4.6) | 0.13% | — | Zscaler MCP ServerAI | 28/9/2026 | 28/9/2026 | Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2. | |
| Analizada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23. | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to… | |
| Modificada | Alta (7) | 0.24% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression… | |
| Analizada | Crítica (9.3) | 0.36% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before… | |
| Analizada | Crítica (9.5) | 1.3% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 28/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute… | |
| Aplazada | Baja (3.8) | 0.23% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators. | |
| Aplazada | Media (5.3) | 0.25% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published. | |
| Pendiente de análisis | Media (4.4) | 0.20% | — | Zscaler Internet AccessAI | 18/9/2026 | 18/9/2026 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances. | |
| Pendiente de análisis | Media (4.4) | 0.11% | — | Dell ECSAIDell ObjectscaleAI | 16/9/2026 | 16/9/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (5.5) | 0.36% | — | Dell Objectscale | 16/9/2026 | 21/9/2026 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Crítica (9.8) | 0.85% | — | Dell Objectscale | 16/9/2026 | 21/9/2026 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Pendiente de análisis | Media (6.7) | 0.15% | — | Dell ECSAIDell ObjectscaleAI | 16/9/2026 | 18/9/2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Crítica (9.1) | 0.48% | — | Dell Objectscale | 16/9/2026 | 21/9/2026 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | |
| Pendiente de análisis | Alta (8.1) | 0.38% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. | |
| Aplazada | Crítica (9.8) | 1.4% | — | Theeventscalendar THE Events CalendarAI | 12/9/2026 | 14/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Theeventscalendar THE Events CalendarAI | 12/9/2026 | 14/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse,… | |
| Analizada | Media (6.7) | 0.53% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting… |