Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes… | |
| Recibida | Alta (7.2) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130). | |
| Recibida | Media (4.3) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating… | |
| Recibida | Media (5.4) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that… | |
| Pendiente de análisis | Media (5.3) | 0.37% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. | |
| Pendiente de análisis | Media (5.1) | 0.33% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory. | |
| Pendiente de análisis | Crítica (9.5) | 0.35% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server. | |
| Pendiente de análisis | Alta (7.5) | 0.51% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account. | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server. | |
| Pendiente de análisis | Crítica (9.5) | 0.36% | — | Perforce P4 SearchAI | 5/10/2026 | 6/10/2026 | Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Internlm MindsearchAI | 4/10/2026 | 6/10/2026 | A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (6.1) | 0.21% | — | Ivorysearch Ivory SearchAI | 3/10/2026 | 6/10/2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.7) | 1.0% | — | Tp-link Archer Ax90AI | 1/10/2026 | 2/10/2026 | A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot. Successful exploitation may result in complete device… | |
| Aplazada | Alta (7.1) | 0.36% | — | 4TU Researchdata DjehutyAI | 1/10/2026 | 2/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:… | |
| Aplazada | Alta (8.4) | 0.30% | — | 4tu.researchdata DjehutyAI | 1/10/2026 | 6/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.… | |
| Pendiente de análisis | Baja (1.2) | 0.30% | 💥 PoC | Wikimedia MediasearchAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Alta (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| Aplazada | Media (5.5) | 0.41% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried… | |
| Aplazada | Media (5.5) | 0.40% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 29/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used.… |