Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-2920
2026-03-16
HIGH
7.8
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library…
CVE-2026-2578
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-2493
2026-03-16
HIGH
7.5
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this…
CVE-2026-2491
2026-03-16
MEDIUM
6.3
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Socomec DIRIS A-40 power monitoring devices. Authentication is…
CVE-2026-2476
2026-03-16
HIGH
7.6
Mattermost Plugins versions
CVE-2026-2463
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-2462
2026-03-16
MEDIUM
6.6
Mattermost versions 11.3.x
CVE-2026-2461
2026-03-16
MEDIUM
4.3
Mattermost Plugins versions
CVE-2026-2458
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-2457
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-2456
2026-03-16
MEDIUM
5.3
Mattermost versions 11.3.x
CVE-2026-2233
2026-03-16
MEDIUM
5.3
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing…
CVE-2026-28522
2026-03-16
MEDIUM
6.5
arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of…
CVE-2026-28521
2026-03-16
HIGH
7.7
arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP…
CVE-2026-28520
2026-03-16
HIGH
8.4
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can…
CVE-2026-28519
2026-03-16
HIGH
8.8
arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server…
CVE-2026-26246
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-26133
2026-03-16
HIGH
7.1
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-25783
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-25780
2026-03-16
MEDIUM
4.3
Mattermost versions 11.3.x
CVE-2026-25083
2026-03-16
HIGH
8.3
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or…
CVE-2026-24458
2026-03-16
HIGH
7.5
Mattermost versions 11.3.x
CVE-2026-21005
2026-03-16
N/A
0.0
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
CVE-2026-21004
2026-03-16
N/A
0.0
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
CVE-2026-21002
2026-03-16
N/A
0.0
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
CVE-2026-21001
2026-03-16
N/A
0.0
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-21000
2026-03-16
N/A
0.0
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
CVE-2026-20999
2026-03-16
N/A
0.0
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
CVE-2026-20998
2026-03-16
N/A
0.0
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
CVE-2026-20997
2026-03-16
N/A
0.0
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
CVE-2026-20996
2026-03-16
N/A
0.0
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
CVE-2026-20995
2026-03-16
N/A
0.0
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
CVE-2026-20994
2026-03-16
N/A
0.0
URL redirection in Samsung Account prior to version 15.5.01.1 allows remote attackers to potentially get access token.
CVE-2026-20993
2026-03-16
N/A
0.0
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.
CVE-2026-20992
2026-03-16
N/A
0.0
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
CVE-2026-20991
2026-03-16
N/A
0.0
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
CVE-2026-20990
2026-03-16
N/A
0.0
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
CVE-2026-20989
2026-03-16
N/A
0.0
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
CVE-2026-20988
2026-03-16
N/A
0.0
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is…
CVE-2026-1948
2026-03-16
MEDIUM
4.3
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function…
CVE-2026-1947
2026-03-16
HIGH
7.5
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the…
CVE-2026-1883
2026-03-16
MEDIUM
4.3
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,…
CVE-2026-1870
2026-03-16
MEDIUM
5.3
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks…
CVE-2026-0977
2026-03-16
MEDIUM
5.1
IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
CVE-2026-0849
2026-03-16
LOW
3.8
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel…
CVE-2026-0639
2026-03-16
LOW
3.3
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2026-0385
2026-03-16
MEDIUM
5.0
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2025-71264
2026-03-16
LOW
3.7
Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
CVE-2025-6969
2026-03-16
MEDIUM
5.0
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2026-2326
2026-03-16
N/A
0.0
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been…
« Anterior
Página 179 de 4217
Siguiente »
Page load link
Go to Top