832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-41989
Libgcrypt General
6.7
MEDIUM
EPSS
0.0%
2026 CWE-787 1 PoC

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

CVE-2026-25603
MR9600 General
6.6
MEDIUM
EPSS
0.0%
2026 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVE-2026-3008
Notepad++ General
6.6
MEDIUM
EPSS
0.0%
2026 1 PoC

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

CVE-2026-0227
Cloud NGFW Networking Cloud
6.6
MEDIUM
EPSS
0.0%
2026 CWE-754 1 PoC

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

CVE-2026-28207
Zen-C General
6.6
MEDIUM
EPSS
0.0%
2026 CWE-78 1 PoC

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` command-line argument. The vulnerability existed in the `main` application logic (specifically in `src/main.c`), where the compiler constructed a shell command string to invoke the backend C compiler. This command string was built by concatenating various arguments, including the user-controlled output fil

CVE-2026-2462
Mattermost Cloud
6.6
MEDIUM
EPSS
0.2%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

CVE-2026-1235
WP eCommerce Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2026-3098
Smart Slider 3 Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2026-43504
Prosody General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-863 2 PoCs

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.

CVE-2026-0722
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2026-3131
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-200 1 PoC

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.

CVE-2026-3590
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-367 1 PoC

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624

CVE-2026-1458
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVE-2026-1710
WooPayments: Integrated WooCommerce Payments Web Windows
6.5
MEDIUM
EPSS
0.1%
2026 CWE-285 1 PoC

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.

CVE-2026-29905
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or thumbnail generation, it triggers a fatal TypeError.

CVE-2026-3938
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-6706
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

CVE-2026-1627
SICK LMS1000 Networking
6.5
MEDIUM
EPSS
0.0%
2026 CWE-327 1 PoC

An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.

CVE-2026-3937
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-2318
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)