Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-8667 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-73624 2026-08-13 HIGH 8.1 GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output…
CVE-2026-7427 2026-08-12 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-73620 2026-08-13 HIGH 8.1 GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary…
CVE-2026-73616 2026-08-13 MEDIUM 6.5 OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can…
CVE-2026-73612 2026-08-13 HIGH 8.1 File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can…
CVE-2026-73608 2026-08-13 HIGH 8.6 SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is…
CVE-2026-73585 2026-08-13 MEDIUM 6.3 A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a…
CVE-2026-73584 2026-08-13 MEDIUM 6.3 A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory.…
CVE-2026-73604 2026-08-13 MEDIUM 6.5 Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive…
CVE-2026-73556 2026-08-13 MEDIUM 5.3 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in…
CVE-2026-73555 2026-08-13 MEDIUM 5.3 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py…
CVE-2026-73507 2026-08-13 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could…
CVE-2026-73506 2026-08-13 MEDIUM 6.1 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata,…
CVE-2026-73491 2026-08-12 N/A 0.0 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs…
CVE-2026-73488 2026-08-13 N/A 0.0 Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data…
CVE-2026-73484 2026-08-13 N/A 0.0 Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit…
CVE-2026-73427 2026-08-12 N/A 0.0 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into…
CVE-2026-73413 2026-08-12 N/A 0.0 Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments…
CVE-2026-73406 2026-08-12 HIGH 7.5 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could…
CVE-2026-73296 2026-08-12 CRITICAL 9.4 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020…
CVE-2026-72508 2026-08-12 CRITICAL 9.9 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating…
CVE-2026-70464 2026-08-13 HIGH 7.5 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after…
CVE-2026-70463 2026-08-13 HIGH 8.1 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly…
CVE-2026-70460 2026-08-13 HIGH 8.1 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using…
CVE-2026-70459 2026-08-13 MEDIUM 5.3 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose…
CVE-2026-70456 2026-08-13 HIGH 8.2 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list.…
CVE-2026-70455 2026-08-13 HIGH 7.5 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses…
CVE-2026-70452 2026-08-13 HIGH 7.4 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control…
CVE-2026-69106 2026-08-12 HIGH 8.8 A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-59507 2026-08-13 CRITICAL 9.3 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
CVE-2026-59506 2026-08-13 CRITICAL 9.3 CWE-306: Missing Authentication for Critical Function
CVE-2026-59505 2026-08-13 HIGH 8.6 CWE-284: Improper Access Control
CVE-2026-63298 2026-08-12 CRITICAL 9.9 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the…
CVE-2026-63297 2026-08-12 CRITICAL 9.9 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When…
CVE-2026-63296 2026-08-12 CRITICAL 9.9 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts…
CVE-2026-63295 2026-08-12 MEDIUM 4.3 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as…
CVE-2026-59504 2026-08-13 CRITICAL 9.1 CWE-602: Client-Side Enforcement of Server-Side Security
CVE-2026-59503 2026-08-13 CRITICAL 9.1 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-59502 2026-08-13 MEDIUM 5.3 CWE-203: Observable Discrepancy
CVE-2026-59501 2026-08-13 HIGH 8.2 CWE-284: Improper Access Control
CVE-2026-59500 2026-08-13 CRITICAL 10.0 CWE-287: Improper Authentication
CVE-2026-59499 2026-08-13 HIGH 8.6 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-53801 2026-08-13 MEDIUM 5.9 rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the…
CVE-2026-53800 2026-08-13 MEDIUM 4.7 rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute…
CVE-2026-53799 2026-08-13 MEDIUM 6.3 rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a…
CVE-2026-53796 2026-08-13 MEDIUM 6.3 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent…
CVE-2026-53795 2026-08-13 HIGH 8.1 rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest…
CVE-2026-53793 2026-08-13 HIGH 7.4 rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary…
CVE-2026-53792 2026-08-13 MEDIUM 6.5 rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer…
« Anterior Página 34 de 4838 Siguiente »