Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

3320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.1)——ElasticsearchAI6/10/20266/10/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes…
RecibidaAlta (7.2)——ElasticsearchAI6/10/20266/10/2026
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
RecibidaMedia (4.3)——ElasticsearchAI6/10/20266/10/2026
Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating…
RecibidaMedia (5.4)——ElasticsearchAI6/10/20266/10/2026
Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which…
RecibidaMedia (6.5)——ElasticsearchAI6/10/20266/10/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that…
Pendiente de análisisMedia (5.3)0.37%—Perforce P4 SearchAI5/10/20266/10/2026
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Pendiente de análisisMedia (5.1)0.33%—Perforce P4 SearchAI5/10/20266/10/2026
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Pendiente de análisisCrítica (9.5)0.35%—Perforce P4 SearchAI5/10/20266/10/2026
P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.
Pendiente de análisisAlta (7.5)0.51%—Perforce P4 SearchAI5/10/20266/10/2026
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.
Pendiente de análisisCrítica (10)0.42%—Perforce P4 SearchAI5/10/20266/10/2026
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.
Pendiente de análisisCrítica (9.5)0.36%—Perforce P4 SearchAI5/10/20266/10/2026
Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.
AplazadaCrítica (9.3)0.77%—Internlm MindsearchAI4/10/20266/10/2026
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to…
AplazadaMedia (6.1)0.21%—Ivorysearch Ivory SearchAI3/10/20266/10/2026
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.7)1.0%—Tp-link Archer Ax90AI1/10/20262/10/2026
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot. Successful exploitation may result in complete device…
AplazadaAlta (7.1)0.36%—4TU Researchdata DjehutyAI1/10/20262/10/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:…
AplazadaAlta (8.4)0.30%—4tu.researchdata DjehutyAI1/10/20266/10/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.…
Pendiente de análisisBaja (1.2)0.30%💥 PoCWikimedia MediasearchAI30/9/20261/10/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.
AplazadaAlta (7.1)0.18%—Yithemes Yith Woocommerce Ajax SearchAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
AplazadaMedia (5.5)0.41%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried…
AplazadaMedia (5.5)0.40%—Trusteddomain OpendmarcAI28/9/202629/9/2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used.…
Orbitaley — Vulnerabilidades