431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-5618
kodbox General
6.3
MEDIUM
EPSS
0.1%
2026 CWE-918 1 PoC

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-8242
Canias ERP General
6.3
MEDIUM
EPSS
0.0%
2026 CWE-204 1 PoC

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-28950
iOS and iPadOS General
6.2
MEDIUM
EPSS
0.0%
2026 2 PoCs

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.

CVE-2026-33947
jq General
6.2
MEDIUM
EPSS
0.0%
2026 CWE-674 1 PoC

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a JSON document containing a flat array of ~65,000 integers (~200 KB) that, when used as a path argument by a trusted jq filter, exhausts the C call stack and crashes the process with a segmentation fault (SIGSEGV). This bypass works because the existing MAX_PARSING_DEPTH (10,000) limit only protects t

CVE-2026-29628
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2026 1 PoC

A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.

CVE-2026-27846
MR9600 General
6.2
MEDIUM
EPSS
0.0%
2026 CWE-306 1 PoC

Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network  to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVE-2026-41950
dify General
6.0
MEDIUM
EPSS
0.0%
2026 CWE-639 1 PoC

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership validation, bypassing workspace separation and signed URL protections to retrieve sensitive file contents through workflow processing.

CVE-2026-2725
Gerrit General
6.0
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.

CVE-2026-4603
jsrsasign General
5.9
MEDIUM
EPSS
0.0%
2026 CWE-369 1 PoC

Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reduction logic in ext/jsbn.js. An attacker can force RSA public-key operations (e.g., verify and encryption) to collapse to deterministic zero outputs and hide “invalid key” errors by supplying a JWK whose modulus decodes to zero.

CVE-2026-24910
Bun General
5.9
MEDIUM
EPSS
0.0%
2026 CWE-348 1 PoC

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

CVE-2026-24909
vlt General
5.9
MEDIUM
EPSS
0.0%
2026 CWE-23 1 PoC

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.

CVE-2026-25904
Software Genérico General
5.8
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

CVE-2026-2454
Mattermost General
5.8
MEDIUM
EPSS
0.1%
2026 CWE-1287 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537

CVE-2026-27656
Mattermost General
5.7
MEDIUM
EPSS
0.0%
2026 CWE-303 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590

CVE-2026-3277
PowerShell Universal General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-312 1 PoC

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials

CVE-2026-6537
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-121 2 PoCs

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-6527
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-674 1 PoC

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-22795
OpenSSL General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-754 1 PoC

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses betwee

CVE-2026-7379
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-401 1 PoC

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVE-2026-7378
Wireshark General
5.5
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service