Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3340▲ 436 respecto a la semana anterior
Críticas / altas1492▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)592▲ 119 respecto a la semana anterior
–

39.713 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.86%—SiteskiteAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
AplazadaCrítica (9)0.63%—Acymailing Smtp NewsletterAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Pendiente de análisisCrítica (9.1)0.23%—Apache Wss4jAI30/9/202630/9/2026
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
AnalizadaCrítica (9.8)1.1%⚠ Explotación activaCisco Catalyst Sd-wan Manager30/9/20261/10/2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request…
AplazadaCrítica (9.2)0.49%—SogoAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was…
AplazadaCrítica (9.3)0.56%—Sogo YHNAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged…
En análisisCrítica (9.8)0.84%—Apache Wss4jAI30/9/202630/9/2026
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix…
Pendiente de análisisCrítica (9.1)0.28%—Apache CXFAI30/9/202630/9/2026
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to…
Pendiente de análisisCrítica (9.1)0.55%—Apache Mina SshdAI30/9/202630/9/2026
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the…
Pendiente de análisisCrítica (9.1)0.55%—Apache Mina SshdAI30/9/202630/9/2026
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and…
Pendiente de análisisCrítica (9.1)0.51%—Apache Mina SshdAI30/9/202630/9/2026
Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous…
AplazadaCrítica (9.3)0.43%—Digiwin Easyflow DOT NETAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
AplazadaCrítica (9.3)0.51%—Digiwin EasyflowAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Pendiente de análisisCrítica (9.2)0.13%—Apache Plc4xAI30/9/202630/9/2026
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by…
AplazadaCrítica (9.1)0.30%—Stellarwp GivewpAI30/9/202630/9/2026
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
AplazadaCrítica (9.8)0.57%—Zella ThemeAI30/9/202630/9/2026
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
Pendiente de análisisCrítica (9.8)0.61%—Pexip InfinityAI30/9/202630/9/2026
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
AplazadaCrítica (9.4)1.5%—AisocAI30/9/202630/9/2026
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path,…
Pendiente de análisisCrítica (9.2)0.33%—Watchguard FirewareAI30/9/20261/10/2026
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
AplazadaCrítica (9.3)0.62%—LightllmAI29/9/202630/9/2026
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
AplazadaCrítica (9.3)0.78%—LightllmAI29/9/202630/9/2026
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to…
Pendiente de análisisCrítica (10)0.44%——29/9/202630/9/2026
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
Pendiente de análisisCrítica (9.4)0.40%——29/9/202630/9/2026
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
Pendiente de análisisCrítica (10)0.34%—ViidureAI29/9/202629/9/2026
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
AplazadaCrítica (9.8)0.29%—Totolink N150rtAI29/9/202630/9/2026
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition…