Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Scim-patchAI | 23/9/2026 | 23/9/2026 | scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled SCIM PATCH paths. A path or one of the dotted value keys beginning with an inherited property such as toString can… | |
| Aplazada | Baja (2.1) | 0.37% | — | Starcounter-jack Json-patchAI | 8/9/2026 | 28/9/2026 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 8/9/2026 | 8/9/2026 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Json PatchAI | 7/9/2026 | 9/9/2026 | A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate… | |
| Aplazada | Media (5.5) | 0.76% | — | Starcounter-jack Json-patchAI | 7/9/2026 | 8/9/2026 | A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Pendiente de análisis | Crítica (9.4) | 1.8% | — | GMS Dispatcher ServiceAI | 11/8/2026 | 28/8/2026 | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests. | |
| Aplazada | Alta (8.6) | 0.50% | — | Duhow Xiaoai-patchAI | 10/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home… | |
| Aplazada | Crítica (9.8) | 1.7% | — | Duhow Xiaoai-patchAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system()… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Scim-patchAI | 7/8/2026 | 18/9/2026 | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide, affecting every plain object in the Node… | |
| Aplazada | Media (5.5) | 0.41% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.47% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Pendiente de análisis | Media (6.3) | 0.26% | — | Tanium PatchAI | 28/7/2026 | 30/7/2026 | Tanium addressed a SQL injection vulnerability in Patch. | |
| Analizada | Media (4.6) | 0.17% | — | GNU Patch | 9/7/2026 | 13/7/2026 | GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting… | |
| Analizada | Media (4.6) | 0.17% | — | GNU Patch | 9/7/2026 | 13/7/2026 | GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during… | |
| Aplazada | Alta (7.8) | 0.67% | — | JsondiffpatchAI | 16/5/2026 | 5/7/2026 | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path… | |
| Aplazada | Baja (2) | 0.33% | — | JsondiffpatchAI | 16/5/2026 | 17/6/2026 | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacker-controlled HTML… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Media (5.7) | 0.17% | — | Canonical Livepatch Client | 20/4/2026 | 17/6/2026 | An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems… | |
| Analizada | Alta (7.8) | 0.22% | — | App-auto-patch | 4/3/2026 | 17/6/2026 | Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. | |
| Analizada | Media (5.5) | 0.67% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is… | |
| Analizada | Media (5.5) | 0.58% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.64% | — | Rongzhitong Visual Integrated Command AND Dispatch Platform | 18/2/2026 | 17/6/2026 | A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to… |