Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-45618 2026-08-11 CRITICAL 10.0 LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
CVE-2026-19091 2026-08-11 HIGH 8.1 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the…
CVE-2026-18860 2026-08-11 HIGH 8.7 Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can…
CVE-2026-18636 2026-08-11 MEDIUM 6.8 The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested…
CVE-2026-17535 2026-08-11 MEDIUM 6.2 Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used…
CVE-2026-17061 2026-08-11 CRITICAL 10.0 A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
CVE-2026-73228 2026-08-11 MEDIUM 5.3 Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser…
CVE-2026-73227 2026-08-11 HIGH 8.1 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server to write attacker-controlled content outside the selected save directory because the RDP clipboard…
CVE-2026-73224 2026-08-11 HIGH 8.8 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder…
CVE-2026-73223 2026-08-11 HIGH 8.1 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name…
CVE-2026-73222 2026-08-11 HIGH 8.8 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js…
CVE-2026-73085 2026-08-11 N/A 0.0 Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on…
CVE-2026-73077 2026-08-11 N/A 0.0 Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands…
CVE-2026-73075 2026-08-11 N/A 0.0 Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and…
CVE-2026-73069 2026-08-11 CRITICAL 9.1 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR…
CVE-2026-72925 2026-08-11 MEDIUM 6.1 SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in…
CVE-2026-72713 2026-08-11 HIGH 7.5 XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments…
CVE-2026-71383 2026-08-11 HIGH 7.3 is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited…
CVE-2026-70335 2026-08-11 HIGH 7.8 Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70311 2026-08-11 HIGH 7.8 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-69117 2026-08-11 MEDIUM 6.5 NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references…
CVE-2026-65782 2026-08-11 HIGH 7.0 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-61923 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
CVE-2026-48802 2026-08-11 HIGH 7.5 python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the…
CVE-2026-48483 2026-08-11 MEDIUM 5.4 TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp marketing/error status events…
CVE-2026-48381 2026-08-11 CRITICAL 9.0 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution…
CVE-2026-48445 2026-08-11 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48438 2026-08-11 HIGH 7.5 CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-48387 2026-08-11 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48376 2026-08-11 MEDIUM 5.4 is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass…
CVE-2026-48056 2026-08-11 CRITICAL 10.0 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing…
CVE-2026-21279 2026-08-11 HIGH 8.2 is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-14180 2026-08-11 MEDIUM 5.3 A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue…
CVE-2026-62882 2026-08-11 MEDIUM 4.3 Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62703 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61936 2026-08-11 MEDIUM 5.5 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
CVE-2026-61368 2026-08-11 MEDIUM 5.0 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61357 2026-08-11 HIGH 7.8 Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-56179 2026-08-11 HIGH 8.3 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-70354 2026-08-11 HIGH 7.8 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-70336 2026-08-11 HIGH 8.8 Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-70327 2026-08-11 MEDIUM 6.5 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70322 2026-08-11 MEDIUM 5.5 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70317 2026-08-11 MEDIUM 5.5 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70312 2026-08-11 MEDIUM 5.5 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70306 2026-08-11 CRITICAL 9.3 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-68821 2026-08-11 HIGH 7.3 Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-66810 2026-08-11 MEDIUM 5.5 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-66809 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-66804 2026-08-11 HIGH 7.8 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
« Anterior Página 58 de 4840 Siguiente »