Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-53791 2026-08-13 CRITICAL 9.1 rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a…
CVE-2026-53789 2026-08-13 MEDIUM 6.5 rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a…
CVE-2026-53788 2026-08-13 MEDIUM 6.5 rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing…
CVE-2026-53786 2026-08-13 MEDIUM 6.5 rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge…
CVE-2026-53784 2026-08-13 HIGH 7.1 rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root…
CVE-2026-53783 2026-08-13 HIGH 8.1 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting…
CVE-2026-49820 2026-08-13 MEDIUM 4.7 Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML,…
CVE-2026-49466 2026-08-12 MEDIUM 6.5 Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and…
CVE-2026-45819 2026-08-13 N/A 0.0 baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
CVE-2026-28154 2026-08-13 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress…
CVE-2026-19484 2026-08-13 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary…
CVE-2026-19696 2026-08-13 MEDIUM 6.6 Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
CVE-2026-19695 2026-08-13 MEDIUM 4.7 Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
CVE-2026-19694 2026-08-13 MEDIUM 4.7 TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
CVE-2026-19481 2026-08-13 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose…
CVE-2026-19642 2026-08-12 MEDIUM 5.9 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in…
CVE-2026-19311 2026-08-12 HIGH 8.1 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a…
CVE-2026-19088 2026-08-13 MEDIUM 5.4 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into…
CVE-2026-19004 2026-08-12 HIGH 8.1 An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to…
CVE-2026-19228 2026-08-12 HIGH 8.5 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated…
CVE-2026-18945 2026-08-13 HIGH 8.2 The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions,…
CVE-2026-18888 2026-08-12 MEDIUM 6.5 The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a…
CVE-2026-18679 2026-08-12 N/A 0.0 When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and…
CVE-2026-18952 2026-08-12 HIGH 8.1 Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read…
CVE-2026-18678 2026-08-12 N/A 0.0 When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.…
CVE-2026-18677 2026-08-12 N/A 0.0 In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that…
CVE-2026-18622 2026-08-13 MEDIUM 4.7 Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents,…
CVE-2026-18433 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated…
CVE-2026-18676 2026-08-12 N/A 0.0 The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from…
CVE-2026-18673 2026-08-12 N/A 0.0 When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to…
CVE-2026-18368 2026-08-13 N/A 0.0 In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected…
CVE-2026-16459 2026-08-13 N/A 0.0 Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via…
CVE-2026-18096 2026-08-12 LOW 3.3 IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
CVE-2026-18148 2026-08-12 MEDIUM 4.3 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
CVE-2026-16494 2026-08-12 HIGH 7.1 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated…
CVE-2026-18244 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-16455 2026-08-13 N/A 0.0 In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate…
CVE-2026-16458 2026-08-13 N/A 0.0 Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements…
CVE-2026-15413 2026-08-13 CRITICAL 10.0 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519…
CVE-2026-15217 2026-08-12 HIGH 8.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-15216 2026-08-12 HIGH 8.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-15423 2026-08-12 HIGH 8.5 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-14332 2026-08-13 MEDIUM 5.4 The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any…
CVE-2026-14298 2026-08-13 MEDIUM 6.5 Mattermost versions 11.9.x
CVE-2026-14213 2026-08-13 LOW 3.7 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any…
CVE-2026-12263 2026-08-13 HIGH 8.8 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
CVE-2026-14182 2026-08-13 CRITICAL 9.8 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy…
CVE-2026-13433 2026-08-12 HIGH 8.3 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could…
CVE-2026-12004 2026-08-12 HIGH 8.7 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string…
CVE-2026-11970 2026-08-13 N/A 0.0 This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
« Anterior Página 35 de 4838 Siguiente »