431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-3040
Vigor 300B General
5.1
MEDIUM
EPSS
0.4%
2026 CWE-78 1 PoC

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor confirms that "300B is EoL, and this is an authenticated vulnerability. We don't plan to fix it." This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-22190
Panda3D General
5.1
MEDIUM
EPSS
0.1%
2026 CWE-134 1 PoC

Panda3D versions up to and including 1.10.16 egg-mkfont contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker provides additional format specifiers, egg-mkfont may read unintended stack values and write the formatted output into generated .egg and .png files, resulting in disclosure of stack-resident memory and pointer values.

CVE-2026-4925
Server General
5.0
MEDIUM
EPSS
0.1%
2026 CWE-862 1 PoC

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.11.

CVE-2026-6845
Red Hat Enterprise Linux 10 General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

CVE-2026-3113
Mattermost General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-732 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593

CVE-2026-5704
Red Hat Enterprise Linux 10 General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-434 2 PoCs

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVE-2026-34262
SAP HANA Cockpit and HANA Database Explorer General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-522 1 PoC

Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

CVE-2026-3116
Mattermost General
4.9
MEDIUM
EPSS
0.1%
2026 CWE-400 1 PoC

Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589

CVE-2026-3221
Server General
4.9
MEDIUM
EPSS
0.0%
2026 CWE-312 1 PoC

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

CVE-2026-2889
CCExtractor General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-416 1 PoC

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.

CVE-2026-22212
TinyOS General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-121 1 PoC

TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility. The vulnerability is caused by unsafe use of strcpy() and strcat() functions when constructing device paths during automatic device discovery. A local attacker can exploit this by creating specially crafted filenames under /dev/usb/, leading to stack memory corruption and application crashes.

CVE-2026-8367
aria2c General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-295 1 PoC

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

CVE-2026-1151
mpay General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-3675
dGEN1 General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-285 1 PoC

A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppReceiver of the component org.ethosmobile.ethoslauncher. Executing a manipulation can lead to improper authorization. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-1417
GPAC General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: f96bd57c3ccdcde4335a0be28cd3e8fe296993de. Applying a patch is the recommended action to fix this issue.

CVE-2026-1858
wget2 General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

CVE-2026-3407
yosys General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

CVE-2026-25616
Blesta General ⚡ nuclei
4.7
MEDIUM
EPSS
2.5%
2026 CWE-79 1 PoC

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

CVE-2026-3201
Wireshark General
4.7
MEDIUM
EPSS
0.0%
2026 CWE-1325 1 PoC

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

CVE-2026-22186
Bio-Formats General
4.6
MEDIUM
EPSS
0.0%
2026 CWE-611 1 PoC

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and external DTD loading. A crafted metadata file can trigger outbound network requests (SSRF), access local system resources where readable, or cause a denial of service during XML parsing.