Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | KindeditorAISem-cms SemcmsAI | 23/9/2026 | 24/9/2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Pendiente de análisis | Media (6.5) | 0.29% | — | Io.netty Netty-codec-memcacheAI | 18/9/2026 | 25/9/2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can… | |
| Aplazada | Media (5.5) | 0.86% | — | MemcachedAI | 14/9/2026 | 15/9/2026 | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released… | |
| Pendiente de análisis | Alta (8.1) | 0.72% | — | Ansible Community.generalAIMemcachedAIPython-memcachedAI | 9/9/2026 | 9/9/2026 | A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached… | |
| Aplazada | Media (5.4) | 0.29% | — | EMC EroomAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | EMC EroomAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | |
| Aplazada | Media (6.8) | 0.16% | — | Samsung SemclipboardserviceAI | 10/7/2026 | 14/7/2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | |
| Pendiente de análisis | Alta (7.7) | 0.32% | — | Bosh Windows Stemcell BuilderAI | 9/7/2026 | 9/7/2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Bosh-ecosystem Bosh-windows-stemcell-builderAI | 9/7/2026 | 9/7/2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected… | |
| Aplazada | Media (6.3) | 0.15% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. | |
| Aplazada | Alta (7.5) | 0.39% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. | |
| Analizada | Alta (8.1) | 0.55% | — | Memcached | 20/5/2026 | 24/7/2026 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | |
| Modificada | Alta (8.1) | 1.3% | — | Memcached | 20/5/2026 | 18/9/2026 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. | |
| Aplazada | Media (6.4) | 0.16% | — | Iobit Advanced SystemcareAI | 5/5/2026 | 17/6/2026 | A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack is characterized by high complexity. It is indicated that the exploitability is… | |
| Aplazada | Media (6.4) | 0.19% | — | EMCAI | 19/4/2026 | 17/6/2026 | The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Baja (1.9) | 1.1% | — | 0xkoda WiremcpAI | 11/3/2026 | 17/6/2026 | A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.38% | — | Sem-cms Semcms | 29/1/2026 | 17/6/2026 | A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Modificada | Crítica (9.8) | 0.98% | — | Sagemcom F@st 3686 Firmware | 12/1/2026 | 5/7/2026 | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request. | |
| Aplazada | Media (5.5) | 0.30% | — | Saiftheboss7 OnlinemcqexamAI | 28/12/2025 | 17/6/2026 | A vulnerability was found in saiftheboss7 onlinemcqexam up to 0e56806132971e49721db3ef01868098c7b42ada. This vulnerability affects unknown code of the file /admin/quesadd.php. Performing manipulation of the argument ans1/ans2 results in sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Media (5.8) | 0.20% | — | EMC EroomAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5.6. | |
| Aplazada | Media (5.3) | 0.31% | — | EMC EroomAI | 25/10/2025 | 17/6/2026 | The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes… | |
| Aplazada | Alta (8.4) | 0.29% | — | EmcliAI | 13/10/2025 | 17/6/2026 | EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution. | |
| Analizada | Media (4.9) | 0.31% | — | Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+108 | 25/9/2025 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell EMC Idrac Service Module | 21/8/2025 | 17/6/2026 | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Analizada | Media (5.3) | 0.12% | — | Dell EMC Idrac Service Module | 21/8/2025 | 17/6/2026 | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. |