Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

379 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.6)0.43%—Dani-garcia VaultwardenAI22/9/202624/9/2026
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status…
AplazadaMedia (6.9)0.19%—McpvaultAIObsidianAI15/9/202630/9/2026
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and…
AplazadaAlta (8.4)0.20%—McpvaultAI15/9/202630/9/2026
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and…
AplazadaAlta (7.1)0.25%—Gallery Private Photo VaultAI14/9/202618/9/2026
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
AplazadaMedia (5.8)0.16%—Hashicorp Vault-jsAI14/9/202630/9/2026
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain…
AnalizadaAlta (7.7)0.58%—Commvault8/9/202611/9/2026
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
AnalizadaAlta (8.7)0.30%—Commvault8/9/20269/9/2026
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
AnalizadaAlta (8.3)0.56%—Commvault8/9/20269/9/2026
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalizadaAlta (8.7)0.50%—Commvault8/9/20269/9/2026
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalizadaAlta (8.7)0.46%—Commvault8/9/20269/9/2026
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalizadaAlta (8.7)0.46%—Commvault8/9/20269/9/2026
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalizadaAlta (8.8)0.47%—Commvault8/9/202611/9/2026
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
AnalizadaAlta (8.8)0.47%—Commvault8/9/202611/9/2026
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
AnalizadaAlta (7.3)0.32%—Commvault8/9/202611/9/2026
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
AnalizadaAlta (8.5)0.18%—Commvault8/9/202611/9/2026
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
AnalizadaCrítica (9.3)0.61%—Commvault8/9/202611/9/2026
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
AplazadaAlta (8.3)0.41%—Helicone VaultmanagerAI3/9/202624/9/2026
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider…
AplazadaAlta (7.9)0.15%—Synergis SoftwireAIStreamvault Sv-100eAIStreamvault Sv-300eAI28/8/20269/9/2026
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
AplazadaAlta (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI26/8/202626/8/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
Pendiente de análisisMedia (6.8)0.28%—Hashicorp VaultAI24/8/202628/8/2026
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}})…
Pendiente de análisisCrítica (9.6)0.35%—Redhat Ansible Automation PlatformAIHashicorp VaultAI18/8/202624/9/2026
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role…
AplazadaBaja (1.3)0.39%—Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI17/8/202620/8/2026
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level…
Pendiente de análisisCrítica (9.6)0.47%—Hashicorp Vault Secrets OperatorAI13/8/202628/8/2026
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a…
AnalizadaAlta (8.8)0.39%—Commvault11/8/20269/9/2026
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
AnalizadaCrítica (9.2)0.63%—Commvault11/8/202611/9/2026
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.