Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.40%—Doco-cdAIDocker ComposeAIDocker SwarmAI11/9/202630/9/2026
Doco-CD es una herramienta de entrega continua GitOps que implementa y actualiza automáticamente proyectos/servicios de Docker Compose y stacks de Swarm. Antes de la versión 0.90.1, un fallo de límite de confianza en la verificación de artefactos OCI permitía que la configuración de implementación proporcionada por el…
AplazadaAlta (7.7)0.51%—SwarmsAI30/7/202630/7/2026
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private,…
AnalizadaBaja (2.1)0.30%—Macrozheng Mall-swarm4/12/202517/6/2026
A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.…
ModificadaBaja (2.1)0.24%—Macrozheng MallMacrozheng Mall-swarm13/11/202517/6/2026
A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was…
AnalizadaBaja (2.1)0.30%—Macrozheng MallMacrozheng Mall-swarm13/11/202517/6/2026
A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder. The manipulation of the argument orderId leads to improper authorization. The attack can be initiated remotely. The exploit has been…
AnalizadaBaja (2.1)0.30%—Macrozheng MallMacrozheng Mall-swarm13/11/202517/6/2026
A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of the argument orderId can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available…
AnalizadaBaja (2.1)0.33%—Macrozheng MallMacrozheng Mall-swarm13/11/202517/6/2026
A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The…
AnalizadaBaja (2.1)0.24%—Macrozheng Mall-swarm13/11/20257/10/2026
Una vulnerabilidad fue identificada en macrozheng mall-swarm hasta 1.0.3. Esto afecta la función updateAttr del archivo /cart/update/attr. Dicha manipulación conduce a autorización indebida. El ataque puede ser realizado desde remoto. El exploit está disponible públicamente y podría ser utilizado. El proveedor fue…
ModificadaMedia (5.4)0.59%—Jenkins Docker Swarm16/8/202317/6/2026
Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control responses from Docker.
ModificadaMedia (6.5)0.61%—Jenkins Self-organizing Swarm Modules3/6/202017/6/2026
Una vulnerabilidad de tipo cross-site request forgery en Jenkins Self-Organizing Swarm Plug-in Modules Plugin versiones 3.20 y anteriores, permite a atacantes agregar o eliminar etiquetas de agente.
ModificadaMedia (4.3)0.66%—Jenkins Self-organizing Swarm Modules3/6/202017/6/2026
Jenkins Self-Organizing Swarm Plug-in Modules Plugin versiones 3.20 y anteriores, no comprueban los permisos en los endpoints de la API que permiten agregar y quitar etiquetas de agente.
ModificadaCrítica (9.3)1.8%—Jenkins Self-organizing Swarm Modules30/4/201917/6/2026
En los Plugin Self-Organizing Swarm y Modules de Jenkins, clientes que usan difusión UDP para encontrar servidores maestros Jenkins no impiden el procesamiento de entidades externas XML al procesar las respuestas, lo que permite a los atacantes no autorizados de la misma red leer de manera arbitraria archivos de…
ModificadaMedia (5.9)0.49%—Jenkins Swarm26/1/201817/6/2026
Jenkins Swarm Plugin Client 2.73.1 y anteriores y 3.4 y anteriores incluía una versión de la biblioteca commons-httpclient con la vulnerabilidad CVE-2012-6153 que verificaba incorrectamente los certificados SSL, volviéndolo susceptible a ataques de Man-in-the-Middle (MitM).
Orbitaley — Vulnerabilidades