Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.68%—Apache Spark2/9/20268/9/2026
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path…
AnalizadaAlta (8.2)0.20%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaMedia (6)0.18%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
AnalizadaAlta (8.2)0.15%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaAlta (8.2)0.15%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
AnalizadaMedia (6)0.13%—Nvidia DGX Spark Uefi25/8/20269/9/2026
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.
Pendiente de análisisAlta (8.7)1.00%—Opensearch SQL PluginAIApache SparkAI13/8/202614/8/2026
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
AplazadaBaja (2.1)0.47%—Perwendel SparkAI26/7/202627/7/2026
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the…
AplazadaCrítica (9.3)0.41%—Unblu SparkAI22/7/202622/7/2026
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore…
AnalizadaMedia (4.2)0.10%—Sparkle-project Sparkle21/7/20265/8/2026
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach…
AnalizadaMedia (6.1)0.34%—Sparkle-project Sparkle21/7/20265/8/2026
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks deeper in the relative path.…
Pendiente de análisisCrítica (9.2)0.31%—Snowflake Spark ConnectorAI14/7/202615/7/2026
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could…
AplazadaMedia (4.8)0.10%—Genspark AI Workspace APPAI14/6/202624/7/2026
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was…
AplazadaMedia (4.3)0.18%—Sparkle WP MetrostoreAI11/6/202626/9/2026
Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.
AplazadaCrítica (10)0.52%—Remotespark SparkviewAI29/5/202621/7/2026
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated…
AplazadaCrítica (10)0.55%—Remote Spark SparkviewAI8/5/202617/6/2026
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
AnalizadaAlta (8.8)5.3%—Apache Spark16/3/202617/6/2026
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of…
AnalizadaAlta (7.5)0.60%—DJI Mavic Mini FirmwareDJI Spark FirmwareDJI Mini SE Firmware4/3/202617/6/2026
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
AplazadaMedia (4.3)0.19%—Sparklewpthemes Fitness FSEAI19/2/202617/6/2026
Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6.
AplazadaMedia (4.3)0.19%—Sparklewpthemes Hello FSEAI19/2/202617/6/2026
Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6.
AplazadaBaja (1.3)0.41%—DJI Mavic MiniAIDJI Mavic AIRAIDJI SparkAIDJI Mavic Mini SEAI2/2/202617/6/2026
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within the local network.…
AnalizadaMedia (6.1)0.26%—Codewithcj Sparkyfitness15/1/202617/6/2026
SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
AnalizadaCrítica (10)3.4%—Blusparkglobal Bluvoyix14/1/202617/6/2026
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaintext passwords of all…
AnalizadaCrítica (10)0.32%—Blusparkglobal Bluvoyix14/1/202617/6/2026
The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send…
AnalizadaCrítica (10)0.75%—Blusparkglobal Bluvoyix14/1/202617/6/2026
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to create a new user with admin privileges. Successful exploitation of this…