Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-27537 2026-08-13 MEDIUM 6.5 Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic
CVE-2026-27536 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms
CVE-2026-27535 2026-08-13 HIGH 7.1 Subscriber Broken Access Control in Solace Extra
CVE-2026-27380 2026-08-13 HIGH 7.2 Editor PHP Object Injection in Car Rental Manager
CVE-2026-27345 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce
CVE-2026-21832 2026-08-13 MEDIUM 4.3 HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting…
CVE-2026-19710 2026-08-13 HIGH 7.3 A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument…
CVE-2026-19716 2026-08-13 N/A 0.0 Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated…
CVE-2026-18750 2026-08-12 MEDIUM 5.3 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin…
CVE-2026-18024 2026-08-13 MEDIUM 4.3 Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value.…
CVE-2026-16241 2026-08-13 LOW 3.8 Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory…
CVE-2026-18749 2026-08-12 CRITICAL 9.8 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member…
CVE-2026-18744 2026-08-12 MEDIUM 6.5 Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses…
CVE-2026-18675 2026-08-12 N/A 0.0 The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a…
CVE-2026-15994 2026-08-13 HIGH 7.0 During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute…
CVE-2026-14681 2026-08-13 MEDIUM 4.2 Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that…
CVE-2026-14679 2026-08-13 HIGH 8.2 Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1…
CVE-2026-14678 2026-08-13 MEDIUM 4.3 Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the…
CVE-2026-14676 2026-08-13 HIGH 8.8 Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants.…
CVE-2026-14673 2026-08-13 LOW 3.8 Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the…
CVE-2026-14672 2026-08-13 MEDIUM 5.3 Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed…
CVE-2026-14668 2026-08-13 HIGH 8.1 Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span…
CVE-2026-14666 2026-08-13 MEDIUM 4.2 Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require…
CVE-2026-14663 2026-08-13 MEDIUM 6.5 Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the…
CVE-2026-14256 2026-08-13 MEDIUM 4.7 ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.
CVE-2026-12036 2026-08-13 HIGH 7.1 An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary…
CVE-2025-62318 2026-08-13 LOW 3.7 HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled…
CVE-2025-62315 2026-08-13 LOW 3.4 HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application,…
CVE-2025-62314 2026-08-13 MEDIUM 5.6 HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms,…
CVE-2025-52640 2026-08-13 MEDIUM 4.7 HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able…
CVE-2026-8667 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-73624 2026-08-13 HIGH 8.1 GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output…
CVE-2026-7427 2026-08-12 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-73620 2026-08-13 HIGH 8.1 GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary…
CVE-2026-73616 2026-08-13 MEDIUM 6.5 OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can…
CVE-2026-73612 2026-08-13 HIGH 8.1 File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can…
CVE-2026-73608 2026-08-13 HIGH 8.6 SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is…
CVE-2026-73585 2026-08-13 MEDIUM 6.3 A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a…
CVE-2026-73584 2026-08-13 MEDIUM 6.3 A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory.…
CVE-2026-73604 2026-08-13 MEDIUM 6.5 Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive…
CVE-2026-73556 2026-08-13 MEDIUM 5.3 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in…
CVE-2026-73555 2026-08-13 MEDIUM 5.3 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py…
CVE-2026-73507 2026-08-13 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could…
CVE-2026-73506 2026-08-13 MEDIUM 6.1 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata,…
CVE-2026-73491 2026-08-12 N/A 0.0 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs…
CVE-2026-73488 2026-08-13 N/A 0.0 Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data…
CVE-2026-73484 2026-08-13 N/A 0.0 Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit…
CVE-2026-73427 2026-08-12 N/A 0.0 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into…
CVE-2026-73413 2026-08-12 N/A 0.0 Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments…
CVE-2026-73406 2026-08-12 HIGH 7.5 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could…
« Anterior Página 33 de 4837 Siguiente »