832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-3930
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-2317
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-4432
YITH WooCommerce Wishlist Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible for unauthenticated attackers to rename any wishlist belonging to any user on the site.

CVE-2026-4927
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-201 1 PoC

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

CVE-2026-2265
Replicator General
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

CVE-2026-1456
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVE-2026-2316
Chrome General
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-2256
ms-agent General
6.5
MEDIUM
EPSS
0.8%
2026 1 PoC

A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.

CVE-2026-20872
Windows 10 Version 1607 Windows
6.5
MEDIUM
EPSS
0.1%
2026 CWE-73 2 PoCs

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-43505
Prosody General
6.5
MEDIUM
EPSS
0.1%
2026 CWE-420 2 PoCs

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.

CVE-2026-20133
🔥 KEV Cisco Catalyst SD-WAN Manager Networking
6.5
MEDIUM
EPSS
1.3%
2026 CWE-200 1 PoC

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.

CVE-2026-1626
SICK LMS1000 Networking
6.5
MEDIUM
EPSS
0.0%
2026 CWE-327 1 PoC

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.

CVE-2026-1504
Chrome Web
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-3114
Mattermost General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-409 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598

CVE-2026-30662
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when creating zip archives. It uses 'ZipArchive::addFromString' combined with 'file_get_contents', which loads the entire content of every selected file into PHP memory. An authenticated attacker can exploit this by requesting a bulk download of large files, triggering an Out-Of-Memory (OOM) condition that causes the PHP-FPM process to terminate (SIGSEGV) and the web server to return a 500 error.

CVE-2026-5758
Protocol-buffers-schema parser Web
6.5
MEDIUM
EPSS
0.2%
2026 1 PoC

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.

CVE-2026-1542
Super Stage WP Web Windows
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2026-1267
Planning Analytics Local General
6.5
MEDIUM
EPSS
0.0%
2026 CWE-200 1 PoC

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

CVE-2026-1900
Link Whisper Free Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

CVE-2026-4079
SQL Chart Builder Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.