431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-43505
Prosody General
6.5
MEDIUM
EPSS
0.1%
2026 CWE-420 2 PoCs

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.

CVE-2026-27663
CPCI85 Central Processing/Communication General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected application contains denial-of-service (DoS) vulnerability. The remote operation mode is susceptible to a resource exhaustion condition when subjected to a high volume of requests. Sending multiple requests can exhaust resources, preventing parameterization and requiring a reset or reboot to restore functionality.

CVE-2026-45181
IDA General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-88 1 PoC

Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.

CVE-2026-38993
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

CVE-2026-3114
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-409 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598

CVE-2026-3937
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-43504
Prosody General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-863 2 PoCs

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.

CVE-2026-3590
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-367 1 PoC

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624

CVE-2026-2318
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-31280
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of Service (DoS) via supplying crafted RFCOMM frames.

CVE-2026-3930
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-3833
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2026 CWE-178 1 PoC

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.

CVE-2026-31156
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.

CVE-2026-2317
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-2265
Replicator General
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

CVE-2026-2316
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-1267
Planning Analytics Local General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-200 1 PoC

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

CVE-2026-3938
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-2256
ms-agent General
6.5
MEDIUM
EPSS
0.8%
2026 1 PoC

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

CVE-2026-8242
Canias ERP General
6.3
MEDIUM
EPSS
0.0%
2026 CWE-204 1 PoC

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.