Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2021-47992 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47991 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47990 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47989 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2021-47988 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37265 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37264 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37263 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37262 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37261 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37260 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37259 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37258 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2020-37257 2026-08-11 N/A 0.0 Rejected reason: This CVE ID has been rejected.
CVE-2026-73159 2026-08-11 N/A 0.0 Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed an HTML string…
CVE-2026-73158 2026-08-11 N/A 0.0 Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets svgIcon as HTML.…
CVE-2026-73157 2026-08-11 N/A 0.0 Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization…
CVE-2026-73156 2026-08-11 N/A 0.0 Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including…
CVE-2026-73155 2026-08-11 N/A 0.0 Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment.…
CVE-2026-73140 2026-08-11 N/A 0.0 Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, comment privacy, ownership,…
CVE-2026-72914 2026-08-10 HIGH 7.5 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked…
CVE-2026-72909 2026-08-10 N/A 0.0 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier…
CVE-2026-51584 2026-08-11 N/A 0.0 An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched…
CVE-2026-51583 2026-08-11 N/A 0.0 An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook…
CVE-2026-48046 2026-08-11 N/A 0.0 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer…
CVE-2026-59701 2026-08-11 HIGH 7.8 A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files.…
CVE-2026-57263 2026-08-11 MEDIUM 6.8 A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256…
CVE-2026-71218 2026-08-11 MEDIUM 5.3 A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without…
CVE-2026-46670 2026-08-11 CRITICAL 9.8 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a…
CVE-2026-19539 2026-08-11 N/A 0.0 Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content…
CVE-2026-19434 2026-08-11 N/A 0.0 Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a…
CVE-2026-19418 2026-08-11 N/A 0.0 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry…
CVE-2026-19391 2026-08-11 MEDIUM 6.5 A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords…
CVE-2026-19411 2026-08-10 LOW 3.9 A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service…
CVE-2026-44401 2026-08-10 MEDIUM 4.8 Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by…
CVE-2026-18972 2026-08-11 CRITICAL 9.6 An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a…
CVE-2026-16053 2026-08-11 HIGH 8.5 Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
CVE-2026-18948 2026-08-10 CRITICAL 9.9 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote…
CVE-2026-18620 2026-08-10 HIGH 7.1 A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged…
CVE-2026-16456 2026-08-10 MEDIUM 6.5 A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads…
CVE-2026-73160 2026-08-11 N/A 0.0 Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal…
CVE-2026-72783 2026-08-11 MEDIUM 6.2 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class.…
CVE-2026-72778 2026-08-11 HIGH 8.8 Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses…
CVE-2026-72771 2026-08-11 N/A 0.0 n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged…
CVE-2026-72766 2026-08-11 N/A 0.0 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields…
CVE-2026-72750 2026-08-11 N/A 0.0 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When…
CVE-2026-72745 2026-08-11 HIGH 7.5 FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (extra count) field of a peer-supplied GSS Wrap token (RFC 4121) is used directly in…
CVE-2026-72610 2026-08-11 MEDIUM 4.3 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of…
CVE-2026-72609 2026-08-11 HIGH 7.1 An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database contents via the…
CVE-2026-72608 2026-08-11 MEDIUM 6.5 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the…
« Anterior Página 66 de 4840 Siguiente »