Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

401.509 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.3)0.95%—Mikrotik RouterosAI2/10/20263/10/2026
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single…
RecibidaBaja (1.9)0.08%—Denuvo Anti TamperAI2/10/20265/10/2026
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
RecibidaAlta (7.1)0.52%—PeazipAI2/10/20262/10/2026
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
RecibidaMedia (5.8)0.22%—Zilliz AttuAI2/10/20265/10/2026
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
RecibidaMedia (4)0.19%—Zilliz AttuAI2/10/20262/10/2026
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
RecibidaAlta (8.7)0.32%——2/10/20263/10/2026
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
RecibidaMedia (6.9)0.25%——2/10/20263/10/2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a…
RecibidaCrítica (9.3)0.34%——2/10/20263/10/2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation…
RecibidaMedia (5.1)0.11%—Wso2 Message BrokerAI2/10/20263/10/2026
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
RecibidaAlta (8.5)0.11%—Armatura ONEAI2/10/20263/10/2026
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
RecibidaAlta (8.6)0.13%—Armatura ONEAI2/10/20263/10/2026
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database…
RecibidaAlta (8.6)0.09%—Armatura ONEAI2/10/20263/10/2026
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a…
RecibidaMedia (6.9)0.20%——2/10/20263/10/2026
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
RecibidaMedia (4.3)0.17%—Kentico XperienceAI2/10/20262/10/2026
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
RecibidaBaja (3.6)0.12%—Mathworks SimulinkAI2/10/20265/10/2026
MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
RechazadaSin puntuar———2/10/20262/10/2026
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78409. Reason: This candidate is a duplicate of CVE-2026-78409. Notes: All CVE users should reference CVE-2026-78409 instead of this candidate
RechazadaSin puntuar———2/10/20262/10/2026
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78410. Reason: This candidate is a duplicate of CVE-2026-78410. Notes: All CVE users should reference CVE-2026-78410 instead of this candidate
RecibidaAlta (7.1)0.26%—UtmstackAI2/10/20265/10/2026
UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can…
RecibidaMedia (6.3)0.26%—UtmstackAI2/10/20265/10/2026
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this…
RecibidaMedia (6.9)0.25%—UtmstackAI2/10/20262/10/2026
UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered…
RecibidaCrítica (9.3)0.55%—UtmstackAI2/10/20265/10/2026
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path…
RecibidaMedia (6.5)0.44%—UtmstackAI2/10/20265/10/2026
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role,…
RecibidaCrítica (9.4)0.53%——2/10/20263/10/2026
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
RecibidaMedia (5.3)0.30%—MultidictAI2/10/20265/10/2026
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value…
RecibidaMedia (5.3)0.29%—Canonical Postgresql OperatorAI2/10/20263/10/2026
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which…