Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.60% | — | SentryAI | 22/9/2026 | 24/9/2026 | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied relocation archive. An authenticated user can craft an archive that causes arbitrary code execution… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Sentry SeerAI | 16/9/2026 | 18/9/2026 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry… | |
| Pendiente de análisis | Media (5.3) | 0.44% | — | Opentelemetry Sentry ExporterAI | 14/9/2026 | 25/9/2026 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute in… | |
| Pendiente de análisis | Alta (8.1) | 1.8% | — | SentryAI | 8/9/2026 | 9/9/2026 | An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. | |
| Aplazada | Media (5.5) | 0.50% | — | Ddfourtwo Sentry-selfhosted-mcpAI | 27/8/2026 | 28/8/2026 | A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Alta (8.2) | 0.34% | — | Dapr SentryAI | 2/7/2026 | 14/7/2026 | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour… | |
| Analizada | Alta (7.5) | 0.47% | — | Sentry | 24/6/2026 | 27/6/2026 | Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This… | |
| Analizada | Crítica (9.8) | 53% | — | Ivanti Standalone Sentry | 9/6/2026 | 23/7/2026 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Ivanti Standalone Sentry | 9/6/2026 | 23/7/2026 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution | |
| Analizada | Alta (8.7) | 0.93% | — | Sentry | 10/5/2026 | 20/7/2026 | Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded… | |
| Analizada | Crítica (9.8) | 0.73% | — | Sentry | 8/5/2026 | 24/7/2026 | Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another… | |
| Aplazada | Media (5.1) | 0.16% | — | Sentry KernelAI | 18/4/2026 | 17/6/2026 | The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7, this can lead to DoS and covert-channels… | |
| Analizada | Media (5.7) | 0.40% | — | Sentry | 18/3/2026 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue. | |
| Analizada | Alta (8.6) | 0.47% | — | Netikus Eventsentry | 24/2/2026 | 17/6/2026 | EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to be set. An attacker who gains temporary… | |
| Analizada | Crítica (9.1) | 0.58% | — | Sentry | 21/2/2026 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry… | |
| Modificada | Media (6.8) | 0.23% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional… | |
| Modificada | Crítica (9.1) | 0.34% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication information during network communication. | |
| Analizada | Media (5.1) | 0.32% | — | IWT Facesentry Access Control System Firmware | 8/1/2026 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginInstall.php that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated input to execute arbitrary JavaScript in victim browsers, potentially stealing authentication… | |
| Analizada | Alta (8.7) | 2.6% | — | IWT Facesentry Access Control System Firmware | 24/12/2025 | 17/6/2026 | FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. | |
| Analizada | Media (5.1) | 0.24% | — | IWT Facesentry Access Control System Firmware | 24/12/2025 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated… | |
| Modificada | Crítica (9.8) | 0.73% | — | IWT Facesentry Access Control System Firmware | 24/12/2025 | 17/6/2026 | FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication. | |
| Aplazada | Media (5.1) | 0.34% | — | Sentry JavascriptAI | 25/11/2025 | 17/6/2026 | Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js application using the Sentry SDK has sendDefaultPii: true it is possible to inadvertently send certain sensitive HTTP headers, including the Cookie header, to Sentry. Those headers would be stored within… | |
| Analizada | Media (5.5) | 0.80% | — | Sentry | 1/7/2025 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and improper handling of authorization code within Sentry to maintain persistence to a user's account. With a… | |
| Aplazada | Media (4.2) | 0.24% | — | SentryAI | 24/6/2025 | 17/6/2026 | In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be… | |
| Aplazada | Crítica (9.1) | 0.61% | — | SentryAI | 15/1/2025 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity… |