Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Weaviate VerbaAI | 4/10/2026 | 6/10/2026 | A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The… | |
| Aplazada | Crítica (9.2) | 0.60% | — | Verba RAG ApplicationAI | 21/7/2026 | 23/7/2026 | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the… | |
| Aplazada | Crítica (9.2) | 0.64% | — | Verba RAGAI | 21/7/2026 | 23/7/2026 | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values.… | |
| Analizada | Media (5.3) | 0.21% | — | Verint Verba Collaboration Compliance AND Quality Management Platform | 14/5/2026 | 17/6/2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,… | |
| Aplazada | Crítica (10) | 1.5% | — | Christopherdewese1099 Verbalize WPAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0. | |
| Modificada | Media (4.6) | 0.49% | — | Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Gd25lk01-3637-c Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring a reformat of the drive after 20 failed unlock attempts) does not work as specified. More than 20 attempts may be made. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428 and Store… | |
| Modificada | Media (4.6) | 0.48% | — | Verbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive… | |
| Modificada | Media (4.6) | 0.32% | — | Verbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (containing the Windows and macOS client software). The content of this emulated CD-ROM drive is stored as an ISO-9660 image in the hidden sectors… | |
| Modificada | Media (5.5) | 0.43% | — | Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Store 'N' GO Secure Portable HDD Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline brute-force attack for determining the correct passcode, and thus gaining unauthorized access to the stored encrypted data. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428 and Store… | |
| Modificada | Media (6.8) | 0.59% | — | Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Store 'N' GO Secure Portable HDD FirmwareVerbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects… | |
| Modificada | Alta (7.5) | 1.8% | — | Verbatim Keypad Secure USB 3.2 GEN 1 FirmwareVerbatim Store 'N' GO Secure Portable HDD FirmwareVerbatim Executive Fingerprint Secure SSD FirmwareVerbatim Fingerprint Secure Portable Hard Drive Firmware | 8/6/2022 | 17/6/2026 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge… | |
| Modificada | Media (6.5) | 1.8% | — | Verint Verba Collaboration Compliance AND Quality Management Platform | 4/10/2018 | 17/6/2026 | Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control. | |
| Modificada | Media (4.6) | 0.30% | — | Verbatim Corporate Secure | 7/1/2010 | 16/6/2026 | Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time. | |
| Modificada | Media (4.6) | 0.32% | — | Verbatim Corporate Secure | 7/1/2010 | 16/6/2026 | Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key. | |
| Modificada | Media (4.6) | 0.39% | — | Verbatim Corporate Secure | 7/1/2010 | 16/6/2026 | Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program. |