Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3052▲ 469 respecto a la semana anterior
Críticas / altas1425▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
5080 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.21% | — | ALL IN ONE WP Security AND FirewallAI | 30/9/2026 | 30/9/2026 | Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. | |
| Aplazada | Alta (8.2) | 0.32% | — | Http4k Security DigestAI | 27/9/2026 | 30/9/2026 | http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless of its value, age, or prior use. Applications relying on… | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Genetec Security CenterAI | 24/9/2026 | 24/9/2026 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails. | |
| Pendiente de análisis | Alta (7.9) | 0.29% | — | Forcepoint Security EngineAI | 23/9/2026 | 23/9/2026 | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0. | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | Apache Sling Security BundleAI | 23/9/2026 | 23/9/2026 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Apache Sling Security BundleAI | 23/9/2026 | 23/9/2026 | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue. | |
| Aplazada | Crítica (9.2) | 0.51% | — | Ltsecurity Ltk3500sfAI | 22/9/2026 | 24/9/2026 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to… | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Aplazada | Media (6.5) | 0.26% | — | Http4k-security-digestAI | 18/9/2026 | 24/9/2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker… | |
| Aplazada | Media (5.3) | 0.42% | — | Really-simple-plugins Really Simple SecurityAI | 18/9/2026 | 18/9/2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. | |
| Pendiente de análisis | Alta (7.7) | 1.5% | — | Manageengine Datasecurity PlusAI | 18/9/2026 | 18/9/2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module. | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Manageengine Datasecurity PlusAI | 18/9/2026 | 18/9/2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Steeltoe.security.authorization.certificateAI | 17/9/2026 | 30/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the… | |
| Pendiente de análisis | Alta (8.7) | 0.82% | — | BC Security EmpireAI | 16/9/2026 | 24/9/2026 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive… | |
| Pendiente de análisis | Alta (8.2) | 0.46% | — | Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could… | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.4) | 0.26% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Crítica (9.9) | 0.30% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | |
| Pendiente de análisis | Alta (8.6) | 0.55% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAICisco Secure Firewall 3100 SeriesAICisco Secure Firewall 4200 SeriesAI | 16/9/2026 | 18/9/2026 | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Cisco Secure Firewall Adaptive Security Appliance ASA SoftwareAICisco Secure Firewall Threat Defense FTD SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload… | |
| Pendiente de análisis | Media (6.8) | 0.34% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to… | |
| Pendiente de análisis | Alta (7.4) | 0.17% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 16/9/2026 | 18/9/2026 | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a… |