Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.33% | — | Openstack CyborgAI | 7/5/2026 | 17/6/2026 | In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares… | |
| Pendiente de análisis | Alta (7.4) | 0.33% | — | Openstack CyborgAI | 7/5/2026 | 17/6/2026 | OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Borg Technology Corporation Borg SPMAI | 23/4/2026 | 17/6/2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Crítica (9.3) | 0.84% | — | Borg Technology Corporation Borg SPMAI | 23/4/2026 | 17/6/2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user. | |
| Aplazada | Crítica (9.3) | 0.90% | — | Borg Technology Corporation Borg SPMAI | 23/4/2026 | 17/6/2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Select-themes Borgholm Marketing Agency ThemeAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6. | |
| Modificada | Alta (7.5) | 1.1% | — | 10N Borgchat | 25/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 0.44% | — | Andersthorborg Advanced Custom Fields\ | 29/12/2023 | 17/6/2026 | Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12. | |
| Modificada | Media (4.7) | 0.11% | — | Borgbackup Borg | 30/8/2023 | 17/6/2026 | borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attacker to fake archives and potentially indirectly cause backup data loss in the repository. The attack requires an attacker to be able to: 1.… | |
| Modificada | Media (5.3) | 0.58% | — | Borg Project Borg | 21/2/2023 | 17/6/2026 | The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them. | |
| Modificada | Alta (8.8) | 1.9% | — | Borgbackup Borg | 8/2/2018 | 17/6/2026 | Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3. | |
| Modificada | Media (5.5) | 0.38% | — | Ciborg Project Ciborg | 10/1/2018 | 17/6/2026 | chef/travis-cookbooks/ci_environment/perlbrew/recipes/default.rb in the ciborg gem 3.0.0 for Ruby allows local users to write to arbitrary files and gain privileges via a symlink attack on /tmp/perlbrew-installer. | |
| Modificada | Media (5.3) | 1.1% | — | Borg | 2/1/2017 | 17/6/2026 | Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive. | |
| Modificada | Media (5.3) | 1.2% | — | Borg Project Borg | 2/1/2017 | 17/6/2026 | Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the list of archives. | |
| Modificada | Alta (7.5) | 1.2% | — | Motionborg WEB Real Estate | 11/1/2007 | 16/6/2026 | SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information. |