Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.85% | — | TouluniverseAIPythonAI | 27/8/2026 | 23/9/2026 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup… | |
| Aplazada | Media (6.5) | 0.36% | — | Universe Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI | 22/7/2026 | 5/8/2026 | Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026. | |
| Analizada | Baja (1.9) | 0.28% | — | Ncsoft Universe | 29/8/2025 | 17/6/2026 | A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit is… | |
| Aplazada | Baja (2.1) | 1.8% | — | AgentuniverseAI | 7/8/2025 | 17/6/2026 | A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (1.9) | 0.21% | — | Lobbyuniverse Lobby | 28/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack… | |
| Analizada | Media (5.3) | 0.43% | — | Gouniverse Golang CMS | 8/9/2024 | 17/6/2026 | A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. The manipulation of the argument alias leads to cross site scripting. The attack can be initiated remotely. Upgrading to version… | |
| Modificada | Alta (7.5) | 0.28% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. | |
| Modificada | Alta (8.8) | 0.90% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process. | |
| Modificada | Crítica (9.8) | 0.92% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes. | |
| Modificada | Alta (8.8) | 0.91% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit. | |
| Modificada | Alta (8.8) | 0.84% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit. | |
| Modificada | Crítica (9.8) | 1.4% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user. | |
| Modificada | Crítica (9.8) | 62% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the… | |
| Modificada | Crítica (9.8) | 61% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user. | |
| Modificada | Crítica (9.8) | 1.4% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user. | |
| Modificada | Alta (7.8) | 0.41% | — | Broadcom CA Automic Dollar Universe | 8/1/2020 | 17/6/2026 | CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA several years after CA Automic Dollar Universe 5.3.3 reached End of Life (EOL) status on April 1, 2015. | |
| Modificada | Media (5.4) | 0.29% | — | Nasa Universe Wallpapers Xeus Project Nasa Universe Wallpapers Xeus | 19/10/2014 | 17/6/2026 | The NASA Universe Wallpapers Xeus (aka com.xeusNASA) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 2.0% | — | Daman371 Bloggeruniverse | 12/9/2011 | 16/6/2026 | SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Universe CMS | 2/10/2009 | 16/6/2026 | SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.6) | 0.88% | — | IBM U2 Universe | 18/8/2003 | 16/6/2026 | uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user. | |
| Modificada | Alta (7.8) | 0.46% | — | IBM U2 Universe | 18/8/2003 | 16/6/2026 | cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files. | |
| Modificada | Alta (7.2) | 0.69% | — | IBM U2 Universe | 18/8/2003 | 16/6/2026 | Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument. | |
| Modificada | Media (5) | 1.1% | — | IBM U2 Universe | 31/7/2002 | 16/6/2026 | IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow. |