Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

575 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.39%—Modsetter SurfsenseAI29/9/20261/10/2026
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The…
AplazadaBaja (2.1)0.23%—Modsetter SurfsenseAI29/9/202629/9/2026
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The…
AplazadaBaja (2.1)1.2%—Modsetter SurfsenseAI29/9/202629/9/2026
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is…
Pendiente de análisisMedia (6.1)0.30%—Netgate PfsenseAIPfblockerngAI25/9/202630/9/2026
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
Pendiente de análisisAlta (8.5)1.0%—Netgate Pfsense PlusAINetgate Pfsense CEAI25/9/202630/9/2026
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write…
AplazadaMedia (6.1)0.13%—Acer NitrosenseAI23/9/202625/9/2026
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged…
AplazadaMedia (6.1)0.35%—Acer NitrosenseAI23/9/202625/9/2026
An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredicatsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to…
AplazadaBaja (1.2)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be…
AplazadaBaja (2.7)0.43%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
AplazadaBaja (1.2)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation…
AplazadaMedia (4.9)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially…
AplazadaMedia (4.9)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
Pendiente de análisisAlta (8.8)0.08%—Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI15/9/202618/9/2026
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.…
Pendiente de análisisMedia (6.8)0.27%—Bosch Sensortec Coines SDKAI10/9/202610/9/2026
An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{coines_read_stream_sensor_data()}} fails to validate the boundaries of the caller-provided destination buffer. Internally, the stream processing mechanism in {{comm_intf_process_stream_response()}}…
Pendiente de análisisAlta (8)0.31%—Boschsensortec Coines SDKAI10/9/202610/9/2026
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided…
Pendiente de análisisMedia (4.3)0.21%—Bosch Bme690 SensorapiAI10/9/202610/9/2026
An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior, specifically within the field data parsing logic in read_all_field_data (bme69x.c). The driver prefetches heater configuration registers into a contiguous 30-byte stack buffer (set_val) mapping…
Pendiente de análisisAlta (8.4)0.19%—Bosch Sensortec Bhi385 SensorapiAI10/9/202610/9/2026
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event…
Pendiente de análisisAlta (7.6)0.25%—Bosch Sensortec Bhi360 SensorapiAI10/9/202610/9/2026
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875).…
Pendiente de análisisCrítica (9)0.47%—Opnsense CoreAI8/9/202625/9/2026
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS…
AplazadaMedia (5.4)0.50%—Netgate Pfsense PlusAINetgate Pfsense CEAI4/9/202614/9/2026
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file
AplazadaMedia (5.4)0.28%—Netgate Pfsense PlusAINetgate Pfsense CEAI4/9/20269/9/2026
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated…
Pendiente de análisisMedia (5.1)1.1%—Pfsense PlusAIPfsense CEAI3/9/20269/9/2026
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value…