Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-67613 2026-08-13 MEDIUM 4.9 CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI…
CVE-2026-65933 2026-08-13 N/A 0.0 A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
CVE-2026-65932 2026-08-13 N/A 0.0 The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
CVE-2026-53797 2026-08-13 MEDIUM 4.7 rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree…
CVE-2026-49857 2026-08-13 HIGH 7.4 auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private…
CVE-2026-49856 2026-08-13 MEDIUM 4.3 @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy…
CVE-2026-49827 2026-08-13 CRITICAL 9.8 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR…
CVE-2026-49481 2026-08-12 CRITICAL 9.6 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence…
CVE-2026-46382 2026-08-13 N/A 0.0 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched…
CVE-2026-19744 2026-08-13 N/A 0.0 Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL…
CVE-2026-19734 2026-08-13 N/A 0.0 Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read…
CVE-2026-19293 2026-08-13 HIGH 8.8 SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See…
CVE-2026-19292 2026-08-13 HIGH 8.8 Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
CVE-2026-19291 2026-08-13 HIGH 8.8 Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
CVE-2026-18428 2026-08-13 HIGH 8.8 A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary…
CVE-2026-16101 2026-08-13 HIGH 8.8 Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
CVE-2026-14456 2026-08-13 HIGH 7.5 Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels…
CVE-2026-12908 2026-08-13 N/A 0.0 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been…
CVE-2026-12236 2026-08-13 MEDIUM 6.5 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. The per-entry stride…
CVE-2024-58374 2026-08-13 HIGH 7.5 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence…
CVE-2019-25765 2026-08-13 HIGH 7.5 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to…
CVE-2026-73266 2026-08-13 HIGH 7.1 A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to…
CVE-2026-66256 2026-08-13 HIGH 7.2 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API…
CVE-2026-59765 2026-08-13 N/A 0.0 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-59109 2026-08-13 HIGH 8.8 SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled…
CVE-2026-58508 2026-08-13 N/A 0.0 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58507 2026-08-13 N/A 0.0 Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58445 2026-08-13 N/A 0.0 Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58444 2026-08-13 N/A 0.0 Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58443 2026-08-13 N/A 0.0 Public-only repository tokens can update private PR head branches
CVE-2026-58442 2026-08-13 N/A 0.0 Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441 2026-08-13 N/A 0.0 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440 2026-08-13 N/A 0.0 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58439 2026-08-13 N/A 0.0 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438 2026-08-13 N/A 0.0 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58437 2026-08-13 N/A 0.0 Repository Visibility Manipulation via Git Push Options
CVE-2026-58436 2026-08-13 N/A 0.0 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435 2026-08-13 N/A 0.0 Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434 2026-08-13 N/A 0.0 Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58433 2026-08-13 N/A 0.0 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58432 2026-08-13 N/A 0.0 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58431 2026-08-13 N/A 0.0 Public-only API token restriction is not enforced on team API routes
CVE-2026-58429 2026-08-13 N/A 0.0 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428 2026-08-13 N/A 0.0 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427 2026-08-13 N/A 0.0 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58425 2026-08-13 N/A 0.0 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58420 2026-08-13 N/A 0.0 Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58417 2026-08-13 N/A 0.0 REST API exposes organization membership of private organizations to public
CVE-2026-58314 2026-08-13 N/A 0.0 Two SSRF findings in Gitea 1.26.2
CVE-2026-57894 2026-08-13 N/A 0.0 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration