863 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-3779
Foxit PDF Editor General
7.8
HIGH
EPSS
0.0%
2026 CWE-416 2 PoCs

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

CVE-2026-3888
Software Genérico General
7.8
HIGH
EPSS
0.0%
2026 CWE-268 1 PoC

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

CVE-2026-21509
🔥 KEV Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
12.5%
2026 CWE-807 2 PoCs

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-24016
ServerView Agents for Windows Windows
7.8
HIGH
EPSS
0.0%
2026 CWE-427 1 PoC

The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the administrator privilege when the installer is executed.

CVE-2026-3989
SGLang General
7.8
HIGH
EPSS
0.0%
2026 1 PoC

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

CVE-2026-24294
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.0%
2026 CWE-287 2 PoCs

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

CVE-2026-24071
Native Access General
7.8
HIGH
EPSS
0.0%
2026 CWE-367 1 PoC

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

CVE-2026-33825
🔥 KEV Microsoft Defender Antimalware Platform General
7.8
HIGH
EPSS
4.9%
2026 CWE-1220 1 PoC

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-24062
Software Center General
7.8
HIGH
EPSS
0.0%
2026 CWE-306 1 PoC

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

CVE-2026-24291
Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
0.0%
2026 CWE-732 1 PoC

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

CVE-2026-30824
Flowise DevOps Web Networking ⚡ nuclei
7.7
HIGH
EPSS
9.4%
2026 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. This issue has been patched in version 3.0.13.

CVE-2026-31851
Nebula 300+ General
7.7
HIGH
EPSS
0.1%
2026 CWE-307 1 PoC

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.

CVE-2026-32606
incus-os General
7.7
HIGH
EPSS
0.0%
2026 CWE-522 1 PoC

IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the system's owner or any tampering of Secure Boot state or kernel (UKI) boot image. That's because in this configuration, the LUKS key is made available by the TPM so long as the system has the expected PCR7 value and the PCR11 policy matches. That default PCR11 policy importantly allows for the TPM to rele

CVE-2026-34222
open-webui General
7.7
HIGH
EPSS
0.0%
2026 CWE-285 1 PoC

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.

CVE-2026-29870
Software Genérico General
7.6
HIGH
EPSS
0.1%
2026 1 PoC

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the intended checkpoint directory. This vulnerability allows attackers to overwrite arbitrary files accessible to the application process, potentially leading to application corruption, privilege escalation, or code execution depending on the deployment context.

CVE-2026-1007
Server General
7.6
HIGH
EPSS
0.0%
2026 CWE-863 1 PoC

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

CVE-2026-29954
Software Genérico Web
7.6
HIGH
EPSS
0.0%
2026 1 PoC

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to download charts, the chartURL is directly concatenated into the command, allowing attackers to inject wget's `--header` option to achieve arbitrary HTTP header injection.

CVE-2026-2476
Mattermost General
7.6
HIGH
EPSS
0.0%
2026 CWE-200 1 PoC

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606

CVE-2026-2469
directorytree/imapengine Web
7.6
HIGH
EPSS
0.0%
2026 CWE-74 1 PoC

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ID commands. This allows attackers to read or delete victim's emails, terminate the victim's session or execute any valid IMAP command on victim's mailbox by including quote characters " or CRLF sequences \r\n in the input.

CVE-2026-1046
Mattermost General
7.6
HIGH
EPSS
0.0%
2026 CWE-939 1 PoC

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577