Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-2920 2026-03-16 HIGH 7.8 GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library…
CVE-2026-2578 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-2493 2026-03-16 HIGH 7.5 IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this…
CVE-2026-2491 2026-03-16 MEDIUM 6.3 Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Socomec DIRIS A-40 power monitoring devices. Authentication is…
CVE-2026-2476 2026-03-16 HIGH 7.6 Mattermost Plugins versions
CVE-2026-2463 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-2462 2026-03-16 MEDIUM 6.6 Mattermost versions 11.3.x
CVE-2026-2461 2026-03-16 MEDIUM 4.3 Mattermost Plugins versions
CVE-2026-2458 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-2457 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-2456 2026-03-16 MEDIUM 5.3 Mattermost versions 11.3.x
CVE-2026-2233 2026-03-16 MEDIUM 5.3 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing…
CVE-2026-28522 2026-03-16 MEDIUM 6.5 arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of…
CVE-2026-28521 2026-03-16 HIGH 7.7 arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP…
CVE-2026-28520 2026-03-16 HIGH 8.4 arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can…
CVE-2026-28519 2026-03-16 HIGH 8.8 arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server…
CVE-2026-26246 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-26133 2026-03-16 HIGH 7.1 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-25783 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-25780 2026-03-16 MEDIUM 4.3 Mattermost versions 11.3.x
CVE-2026-25083 2026-03-16 HIGH 8.3 GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or…
CVE-2026-24458 2026-03-16 HIGH 7.5 Mattermost versions 11.3.x
CVE-2026-21005 2026-03-16 N/A 0.0 Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
CVE-2026-21004 2026-03-16 N/A 0.0 Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
CVE-2026-21002 2026-03-16 N/A 0.0 Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
CVE-2026-21001 2026-03-16 N/A 0.0 Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-21000 2026-03-16 N/A 0.0 Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-20999 2026-03-16 N/A 0.0 Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
CVE-2026-20998 2026-03-16 N/A 0.0 Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20997 2026-03-16 N/A 0.0 Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
CVE-2026-20996 2026-03-16 N/A 0.0 Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
CVE-2026-20995 2026-03-16 N/A 0.0 Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
CVE-2026-20994 2026-03-16 N/A 0.0 URL redirection in Samsung Account prior to version 15.5.01.1 allows remote attackers to potentially get access token.
CVE-2026-20993 2026-03-16 N/A 0.0 Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
CVE-2026-20992 2026-03-16 N/A 0.0 Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
CVE-2026-20991 2026-03-16 N/A 0.0 Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
CVE-2026-20990 2026-03-16 N/A 0.0 Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
CVE-2026-20989 2026-03-16 N/A 0.0 Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
CVE-2026-20988 2026-03-16 N/A 0.0 Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is…
CVE-2026-1948 2026-03-16 MEDIUM 4.3 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function…
CVE-2026-1947 2026-03-16 HIGH 7.5 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the…
CVE-2026-1883 2026-03-16 MEDIUM 4.3 The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,…
CVE-2026-1870 2026-03-16 MEDIUM 5.3 The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks…
CVE-2026-0977 2026-03-16 MEDIUM 5.1 IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
CVE-2026-0849 2026-03-16 LOW 3.8 Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel…
CVE-2026-0639 2026-03-16 LOW 3.3 in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2026-0385 2026-03-16 MEDIUM 5.0 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-71264 2026-03-16 LOW 3.7 Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
CVE-2025-6969 2026-03-16 MEDIUM 5.0 in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2026-2326 2026-03-16 N/A 0.0 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been…
« Anterior Página 179 de 4217 Siguiente »