Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.21% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as… | |
| Aplazada | Alta (7.6) | 0.23% | — | Edgelesssys ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying… | |
| Aplazada | Alta (8.5) | 0.19% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes… | |
| Aplazada | Media (5.1) | 0.16% | — | Edgeless Systems ContrastAI | 27/9/2026 | 30/9/2026 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when… | |
| Aplazada | Alta (8.5) | 0.21% | — | Edgelesssys ContrastAI | 27/9/2026 | 28/9/2026 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list… | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Poly CCXAIPoly TrioAIPoly Edge EAI | 1/7/2026 | 2/7/2026 | The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | — | Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI | 16/4/2026 | 17/6/2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks | |
| Aplazada | Media (5.1) | 0.16% | — | Ecessa Edge Ev150AI | 24/12/2025 | 17/6/2026 | Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to add superuser accounts… | |
| Aplazada | Media (6.1) | 0.64% | — | Evertz Microsystems Mvip-iiAIEvertz Microsystems Xps-edgeAIEvertz Microsystems Evedge-eoAIEvertz Microsystems Mma10gAI+1 | 14/5/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters. | |
| Modificada | Alta (8.8) | 1.1% | — | Progress OpenedgeProgress Openedge ExplorerProgress Openedge Management | 23/6/2023 | 17/6/2026 | In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through… | |
| Modificada | Alta (8.8) | 0.42% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 3.5% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via… | |
| Modificada | Media (5.3) | 0.44% | — | Siemens Sicam Gridedge Essential ARMSiemens Sicam Gridedge Essential GDS ARMSiemens Sicam Gridedge Essential GDS IntelSiemens Sicam Gridedge Essential Intel | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on which SICAM GridEdge runs to inject a custom SSH key to that file. | |
| Modificada | Media (6.9) | 0.61% | — | Siemens Sicam Gridedge Essential | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another user's password hash. | |
| Modificada | Crítica (9.3) | 1.1% | — | Siemens Sicam Gridedge Essential | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to create a new user with administrative permissions. | |
| Modificada | Alta (8.6) | 0.75% | — | Siemens Sicam Gridedge Essential | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case that user's id is known. | |
| Modificada | Alta (8.6) | 0.40% | — | Siemens Sicam Gridedge Essential | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource a malicious request could be executed. | |
| Modificada | Alta (8.8) | 3.3% | — | Msedgeredirect Project Msedgeredirect | 20/12/2021 | 17/6/2026 | MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability requires user interaction and the acceptance of a prompt. With how MSEdgeRedirect… | |
| Modificada | Alta (7.8) | 0.38% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+144 | 18/8/2017 | 17/6/2026 | A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+70 | 30/11/2016 | 17/6/2026 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be… | |
| Modificada | Alta (7.5) | 2.7% | — | Edgetechweb Event Registration | 14/9/2011 | 16/6/2026 | SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action. | |
| Modificada | Media (4.3) | 1.2% | — | Cutting Edge Computing Edge Ecommerce Shop | 22/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge eCommerce Shop allows remote attackers to inject arbitrary web script or HTML via the cart_id parameter. | |
| Modificada | Alta (7.5) | 4.6% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token. | |
| Modificada | Media (6.4) | 4.3% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2)… | |
| Modificada | Alta (7.5) | 4.5% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID. |