Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.6%⚠ Explotación activaMikrotik Routeros5/9/202611/9/2026
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted…
AnalizadaMedia (6.9)1.0%⚠ Explotación activa💥 PoCMikrotik Routeros5/9/202626/9/2026
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and…
AnalizadaAlta (8.8)49%⚠ Explotación activa💥 PoCGoogle ChromeGoogle V83/9/202621/9/2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (10)8.8%⚠ Explotación activa💥 ExploitSonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware1/9/20263/9/2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
AnalizadaAlta (7.8)11%⚠ Explotación activa💥 ExploitSonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware1/9/202621/9/2026
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary…
AnalizadaCrítica (9.8)14%⚠ Explotación activa💥 ExploitJfrog Artifactory28/8/20263/9/2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
AnalizadaCrítica (9.4)61%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG28/8/202614/9/2026
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system…
AnalizadaAlta (8.8)85%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG28/8/202614/9/2026
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated…
AnalizadaCrítica (9.8)24%⚠ Explotación activa💥 ExploitGitea26/8/202627/8/2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
AnalizadaCrítica (9.5)1.7%⚠ Explotación activa💥 PoCTrueconf Server19/8/202621/8/2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
AnalizadaCrítica (9.3)1.5%⚠ Explotación activaTrueconf Server19/8/202621/8/2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
AnalizadaCrítica (9.3)23%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/8/202610/9/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
AnalizadaCrítica (9.3)9.8%⚠ Explotación activa💥 ExploitLfprojects Mlflow17/8/20265/10/2026
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while…
AnalizadaAlta (8.9)72%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite13/8/202624/8/2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted…
AnalizadaAlta (7.5)9.8%⚠ Explotación activa💥 ExploitJfrog Artifactory12/8/20261/10/2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
AnalizadaMedia (5.3)0.66%⚠ Explotación activa💥 PoCJfrog Artifactory12/8/202628/8/2026
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
AnalizadaAlta (7)0.33%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.6)1.0%⚠ Explotación activaCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense11/8/202616/9/2026
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,…
AnalizadaCrítica (9.1)88%⚠ Explotación activa💥 ExploitAdobe CommerceAdobe Commerce B2BAdobe Magento11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
AnalizadaAlta (8.8)2.1%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server11/8/202626/9/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaCrítica (10)19%⚠ Explotación activa💥 ExploitMetabase10/8/202612/8/2026
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
AnalizadaCrítica (9.8)1.7%⚠ Explotación activa💥 PoCApple Macos6/8/202615/9/2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
AnalizadaCrítica (10)0.59%⚠ Explotación activa💥 PoCWso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/8/202625/9/2026
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result…
AnalizadaAlta (8.2)15%⚠ Explotación activa💥 ExploitN-able N-central2/8/20264/8/2026
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
AnalizadaAlta (8.2)7.9%⚠ Explotación activa💥 PoCN-able N-central1/8/20265/8/2026
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Orbitaley — Vulnerabilidades