832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-28387
OpenSSL General
8.1
HIGH
EPSS
0.0%
2026 CWE-416 1 PoC

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs

CVE-2026-42945
NGINX Plus Web
8.1
HIGH
EPSS
0.1%
2026 CWE-122 1 PoC

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Addres

CVE-2026-24840
dokploy DevOps Web
8.0
HIGH
EPSS
0.1%
2026 CWE-798 1 PoC

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contains a patch for the issue.

CVE-2026-2361
PostgreSQL Anonymizer Database
8.0
HIGH
EPSS
0.1%
2026 CWE-427 1 PoC

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can be exploited by users having the CREATE privilege in PostgreSQL 15 and later. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version because the creation permission on the public schema is granted by default. The problem is resolved

CVE-2026-3108
Mattermost General
8.0
HIGH
EPSS
0.0%
2026 CWE-150 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: MMSA-2026-00599

CVE-2026-0752
GitLab DevOps
8.0
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

CVE-2026-4802
Red Hat Enterprise Linux 10 General
8.0
HIGH
EPSS
0.2%
2026 CWE-78 1 PoC

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVE-2026-24291
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.0%
2026 CWE-732 1 PoC

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

CVE-2026-3989
SGLang General
7.8
HIGH
EPSS
0.0%
2026 1 PoC

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

CVE-2026-27750
Avira Internet Security General
7.8
HIGH
EPSS
0.0%
2026 CWE-367 2 PoCs

Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local attacker can replace a previously scanned directory with a junction or reparse point before deletion occurs, causing the privileged process to delete an unintended system location. This may result in deletion of protected files or directories and can lead to local privilege escalation,

CVE-2026-31431
🔥 KEV Linux General
7.8
HIGH
EPSS
2.6%
2026 22 PoCs

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE-2026-3775
Foxit PDF Editor General
7.8
HIGH
EPSS
0.0%
2026 CWE-427 1 PoC

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.

CVE-2026-22163
Graphics DDK General
7.8
HIGH
EPSS
0.0%
2026 CWE-820 1 PoC

Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.

CVE-2026-3779
Foxit PDF Editor General
7.8
HIGH
EPSS
0.0%
2026 CWE-416 2 PoCs

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

CVE-2026-27749
Avira Internet Security General
7.8
HIGH
EPSS
0.1%
2026 CWE-502 2 PoCs

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.

CVE-2026-33825
🔥 KEV Microsoft Defender Antimalware Platform General
7.8
HIGH
EPSS
4.9%
2026 CWE-1220 1 PoC

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-21533
🔥 KEV Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
20.2%
2026 CWE-269 2 PoCs

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

CVE-2026-26738
Software Genérico General
7.8
HIGH
EPSS
0.1%
2026 2 PoCs

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

CVE-2026-24071
Native Access General
7.8
HIGH
EPSS
0.0%
2026 CWE-367 1 PoC

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

CVE-2026-24016
ServerView Agents for Windows Windows
7.8
HIGH
EPSS
0.0%
2026 CWE-427 1 PoC

The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the administrator privilege when the installer is executed.