Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-24059 2026-08-13 N/A 0.0 The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only…
CVE-2026-23603 2026-08-13 N/A 0.0 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-13051 2026-08-13 N/A 0.0 Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext…
CVE-2026-13048 2026-08-13 N/A 0.0 Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.…
CVE-2022-4993 2026-08-13 N/A 0.0 HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a…
CVE-2026-73671 2026-08-13 MEDIUM 6.1 Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed…
CVE-2026-73670 2026-08-13 HIGH 7.2 A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying…
CVE-2026-73583 2026-08-13 MEDIUM 6.6 A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing.…
CVE-2026-73628 2026-08-13 MEDIUM 6.1 Serendipity versions >= 2.3.5 and
CVE-2026-73576 2026-08-13 MEDIUM 6.3 In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient…
CVE-2026-73575 2026-08-13 LOW 3.1 In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation…
CVE-2026-73574 2026-08-13 LOW 3.1 In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An…
CVE-2026-73573 2026-08-13 LOW 3.1 In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated…
CVE-2026-73572 2026-08-13 MEDIUM 6.1 In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during…
CVE-2026-73571 2026-08-13 LOW 3.1 An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted…
CVE-2026-73570 2026-08-13 HIGH 8.9 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization…
CVE-2026-73559 2026-08-13 MEDIUM 6.5 vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq()…
CVE-2026-73533 2026-08-13 CRITICAL 9.8 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue…
CVE-2026-73532 2026-08-13 CRITICAL 9.8 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue…
CVE-2026-73558 2026-08-13 MEDIUM 5.3 vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel…
CVE-2026-73509 2026-08-13 HIGH 7.6 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates…
CVE-2026-73505 2026-08-13 HIGH 7.8 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names,…
CVE-2026-73403 2026-08-13 MEDIUM 5.3 Unauthenticated Broken Access Control in User Registration
CVE-2026-73401 2026-08-13 MEDIUM 5.3 Unauthenticated Broken Access Control in InstaWP Connect
CVE-2026-73357 2026-08-13 MEDIUM 6.5 Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
CVE-2026-73353 2026-08-13 MEDIUM 5.3 Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-73349 2026-08-13 MEDIUM 5.3 Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-73346 2026-08-13 HIGH 7.6 Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73344 2026-08-13 MEDIUM 5.9 Author Cross Site Scripting (XSS) in WP Data Access
CVE-2026-73340 2026-08-13 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Featured Image from URL
CVE-2026-73419 2026-08-12 MEDIUM 6.8 NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies…
CVE-2026-73188 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in KiviCare
CVE-2026-70462 2026-08-13 MEDIUM 6.5 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive…
CVE-2026-70458 2026-08-13 HIGH 8.2 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while…
CVE-2026-70454 2026-08-13 HIGH 8.0 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting…
CVE-2026-6471 2026-08-13 HIGH 7.2 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…
CVE-2026-6821 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-6387 2026-08-13 HIGH 7.0 A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
CVE-2026-6469 2026-08-13 LOW 3.8 Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run…
CVE-2026-6464 2026-08-13 HIGH 8.1 Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM…
CVE-2026-67991 2026-08-13 HIGH 7.5 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive…
CVE-2026-67990 2026-08-13 MEDIUM 5.4 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that…
CVE-2026-67986 2026-08-13 HIGH 8.4 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval…
CVE-2026-66704 2026-08-13 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion
CVE-2026-66700 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover
CVE-2026-66698 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SureDash
CVE-2026-66697 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
CVE-2026-66693 2026-08-13 MEDIUM 6.5 Subscriber Broken Access Control in Motors
CVE-2026-66691 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Access Control in Nokri
CVE-2026-66689 2026-08-13 MEDIUM 6.3 Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker