Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2021-47992
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47991
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47990
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47989
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2021-47988
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37265
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37264
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37263
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37262
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37261
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37260
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37259
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37258
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2020-37257
2026-08-11
N/A
0.0
Rejected reason: This CVE ID has been rejected.
CVE-2026-73159
2026-08-11
N/A
0.0
Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed an HTML string…
CVE-2026-73158
2026-08-11
N/A
0.0
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets svgIcon as HTML.…
CVE-2026-73157
2026-08-11
N/A
0.0
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization…
CVE-2026-73156
2026-08-11
N/A
0.0
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including…
CVE-2026-73155
2026-08-11
N/A
0.0
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment.…
CVE-2026-73140
2026-08-11
N/A
0.0
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, comment privacy, ownership,…
CVE-2026-72914
2026-08-10
HIGH
7.5
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked…
CVE-2026-72909
2026-08-10
N/A
0.0
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier…
CVE-2026-51584
2026-08-11
N/A
0.0
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched…
CVE-2026-51583
2026-08-11
N/A
0.0
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook…
CVE-2026-48046
2026-08-11
N/A
0.0
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer…
CVE-2026-59701
2026-08-11
HIGH
7.8
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files.…
CVE-2026-57263
2026-08-11
MEDIUM
6.8
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256…
CVE-2026-71218
2026-08-11
MEDIUM
5.3
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without…
CVE-2026-46670
2026-08-11
CRITICAL
9.8
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a…
CVE-2026-19539
2026-08-11
N/A
0.0
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content…
CVE-2026-19434
2026-08-11
N/A
0.0
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a…
CVE-2026-19418
2026-08-11
N/A
0.0
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry…
CVE-2026-19391
2026-08-11
MEDIUM
6.5
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords…
CVE-2026-19411
2026-08-10
LOW
3.9
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service…
CVE-2026-44401
2026-08-10
MEDIUM
4.8
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by…
CVE-2026-18972
2026-08-11
CRITICAL
9.6
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a…
CVE-2026-16053
2026-08-11
HIGH
8.5
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
CVE-2026-18948
2026-08-10
CRITICAL
9.9
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote…
CVE-2026-18620
2026-08-10
HIGH
7.1
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged…
CVE-2026-16456
2026-08-10
MEDIUM
6.5
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads…
CVE-2026-73160
2026-08-11
N/A
0.0
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal…
CVE-2026-72783
2026-08-11
MEDIUM
6.2
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class.…
CVE-2026-72778
2026-08-11
HIGH
8.8
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses…
CVE-2026-72771
2026-08-11
N/A
0.0
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged…
CVE-2026-72766
2026-08-11
N/A
0.0
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields…
CVE-2026-72750
2026-08-11
N/A
0.0
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When…
CVE-2026-72745
2026-08-11
HIGH
7.5
FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (extra count) field of a peer-supplied GSS Wrap token (RFC 4121) is used directly in…
CVE-2026-72610
2026-08-11
MEDIUM
4.3
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of…
CVE-2026-72609
2026-08-11
HIGH
7.1
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database contents via the…
CVE-2026-72608
2026-08-11
MEDIUM
6.5
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the…
« Anterior
Página 66 de 4840
Siguiente »
Page load link
Go to Top