Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
400.513 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted,… | |
| Recibida | Alta (8.8) | — | — | Windriver VxworksAI | 1/10/2026 | 1/10/2026 | An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with… | |
| Recibida | Baja (2.1) | — | — | KatexAI | 1/10/2026 | 1/10/2026 | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited… | |
| Recibida | Crítica (9.3) | — | — | CapacitorAI | 1/10/2026 | 1/10/2026 | Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to… | |
| Pendiente de análisis | Media (6.5) | — | — | KeycloakAI | 1/10/2026 | 1/10/2026 | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive… | |
| Aplazada | Alta (8.7) | — | — | Tp-link Tapo C120AITp-link Tapo C200AI | 1/10/2026 | 1/10/2026 | Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible… | |
| Aplazada | Alta (8.5) | — | — | Tp-link Tl-wr841nAI | 1/10/2026 | 1/10/2026 | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute arbitrary operating system commands. Successful exploitation may allow… | |
| Recibida | Alta (8.2) | — | — | ZODAI | 1/10/2026 | 1/10/2026 | Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which… | |
| Pendiente de análisis | Crítica (9.1) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under… | |
| Pendiente de análisis | Crítica (9.9) | — | — | Theforeman ForemanAI | 1/10/2026 | 1/10/2026 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling… | |
| Pendiente de análisis | Alta (8.8) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. | |
| Pendiente de análisis | Media (5.3) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Recibida | Media (4) | — | — | GeopyAI | 1/10/2026 | 1/10/2026 | geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder reverse methods also… | |
| Recibida | Alta (8.4) | — | — | 4tu.researchdata DjehutyAI | 1/10/2026 | 1/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.… | |
| Pendiente de análisis | Alta (7.3) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.… | |
| Pendiente de análisis | Alta (8.1) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry… | |
| Pendiente de análisis | Baja (3.7) | — | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | |
| Pendiente de análisis | Media (5.3) | — | — | HCL Bigfix Service ManagementAI | 1/10/2026 | 1/10/2026 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version… | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname… | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.… | |
| Pendiente de análisis | Crítica (9.8) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Alta (7.5) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Pendiente de análisis | Media (5.3) | — | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… |