Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-57886
2026-08-13
N/A
0.0
Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-56750
2026-08-13
N/A
0.0
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-56654
2026-08-13
N/A
0.0
Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-56443
2026-08-13
N/A
0.0
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-55987
2026-08-13
N/A
0.0
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-55986
2026-08-13
N/A
0.0
Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-55984
2026-08-13
N/A
0.0
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-55982
2026-08-13
N/A
0.0
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-54481
2026-08-13
N/A
0.0
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
CVE-2026-50105
2026-08-13
N/A
0.0
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-24059
2026-08-13
N/A
0.0
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only…
CVE-2026-23603
2026-08-13
N/A
0.0
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-13051
2026-08-13
N/A
0.0
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext…
CVE-2022-4993
2026-08-13
N/A
0.0
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a…
CVE-2026-73671
2026-08-13
MEDIUM
6.1
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed…
CVE-2026-73670
2026-08-13
HIGH
7.2
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying…
CVE-2026-73583
2026-08-13
MEDIUM
6.6
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing.…
CVE-2026-73628
2026-08-13
MEDIUM
6.1
Serendipity versions >= 2.3.5 and
CVE-2026-73576
2026-08-13
MEDIUM
6.3
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient…
CVE-2026-73575
2026-08-13
LOW
3.1
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation…
CVE-2026-73574
2026-08-13
LOW
3.1
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An…
CVE-2026-73573
2026-08-13
LOW
3.1
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated…
CVE-2026-73572
2026-08-13
MEDIUM
6.1
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during…
CVE-2026-73571
2026-08-13
LOW
3.1
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted…
CVE-2026-73570
2026-08-13
HIGH
8.9
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization…
CVE-2026-73559
2026-08-13
MEDIUM
6.5
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list[int]], prompt_to_seq()…
CVE-2026-73533
2026-08-13
CRITICAL
9.8
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue…
CVE-2026-73532
2026-08-13
CRITICAL
9.8
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue…
CVE-2026-73558
2026-08-13
MEDIUM
5.3
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel…
CVE-2026-73509
2026-08-13
HIGH
7.6
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates…
CVE-2026-73505
2026-08-13
HIGH
7.8
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names,…
CVE-2026-73403
2026-08-13
MEDIUM
5.3
Unauthenticated Broken Access Control in User Registration
CVE-2026-73401
2026-08-13
MEDIUM
5.3
Unauthenticated Broken Access Control in InstaWP Connect
CVE-2026-73357
2026-08-13
MEDIUM
6.5
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
CVE-2026-73353
2026-08-13
MEDIUM
5.3
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-73349
2026-08-13
MEDIUM
5.3
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-73346
2026-08-13
HIGH
7.6
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73344
2026-08-13
MEDIUM
5.9
Author Cross Site Scripting (XSS) in WP Data Access
CVE-2026-73340
2026-08-13
MEDIUM
6.5
Contributor Cross Site Scripting (XSS) in Featured Image from URL
CVE-2026-73419
2026-08-12
MEDIUM
6.8
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies…
CVE-2026-73188
2026-08-13
HIGH
7.5
Unauthenticated Sensitive Data Exposure in KiviCare
CVE-2026-70462
2026-08-13
MEDIUM
6.5
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive…
CVE-2026-70458
2026-08-13
HIGH
8.2
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while…
CVE-2026-70454
2026-08-13
HIGH
8.0
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting…
CVE-2026-6471
2026-08-13
HIGH
7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…
CVE-2026-6821
2026-08-12
MEDIUM
4.3
GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-6387
2026-08-13
HIGH
7.0
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
CVE-2026-6469
2026-08-13
LOW
3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run…
CVE-2026-6464
2026-08-13
HIGH
8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM…
CVE-2026-67991
2026-08-13
HIGH
7.5
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive…
« Anterior
Página 6 de 4814
Siguiente »
Page load link
Go to Top