Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.21%—Amazon Awslabs.dynamodb-mcp-serverAI4/9/20268/9/2026
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model…
AnalizadaAlta (8.2)0.69%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AnalizadaMedia (5.3)0.46%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaMedia (6.5)0.41%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AnalizadaMedia (6.5)0.41%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
AnalizadaAlta (8.1)0.77%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.82%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.55%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
AnalizadaCrítica (9.8)0.89%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
AnalizadaAlta (8.2)0.64%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AplazadaBaja (3.7)0.24%—Amazon AWS SDK FOR .netAIAmazon S3AIAmazon DynamodbAIAmazon GlacierAI10/1/202617/6/2026
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related…
ModificadaCrítica (9.8)1.9%—Dynamoosejs Dynamoose8/2/202117/6/2026
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We…
ModificadaAlta (7.8)0.38%—Autodesk Dynamo BIM17/4/202017/6/2026
An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files.
ModificadaMedia (5)6.4%—Ecometry Sgdynamo29/5/200216/6/2026
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.
ModificadaMedia (5)1.1%—Sybase Powerdynamo11/4/200016/6/2026
The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.