Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.40%—VictoriametricsAI20/8/202618/9/2026
VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageDataPath. An attacker…
AplazadaBaja (2.9)0.75%—VictoriametricsAI15/8/202620/8/2026
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out…
AnalizadaMedia (6.8)0.46%—Redhat Cost Management Metrics Operator30/7/202612/8/2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this…
AnalizadaAlta (7.6)0.32%—Redhat Cost Management Metrics Operator30/7/202612/8/2026
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,…
AnalizadaMedia (6.8)0.39%—Redhat Cost Management Metrics Operator30/7/202617/8/2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent…
AnalizadaMedia (6.5)0.40%—Pevans Metrics\10/6/202623/6/2026
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a…
AnalizadaCrítica (9.1)0.55%—Pevans Metrics\10/6/202624/6/2026
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has…
AnalizadaAlta (8.2)0.50%—Pevans Metrics\10/6/202624/6/2026
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and…
Pendiente de análisisCrítica (9.2)0.31%—AMD Device Metrics ExporterAI15/5/202617/6/2026
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
AplazadaMedia (5.3)0.52%—ExactmetricsAI24/4/202614/8/2026
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin…
AplazadaAlta (7.2)1.00%—ExactmetricsAI23/4/202617/6/2026
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the…
AplazadaMedia (5.4)0.28%—TextmetricsAI13/3/202617/6/2026
Vulnerabilidad de autorización faltante en Israpil Textmetrics webtexttool permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Textmetrics: desde n/a hasta <= 3.6.4.
AplazadaAlta (8.8)0.39%—ExactmetricsAI11/3/202617/6/2026
El plugin ExactMetrics – Google Analytics Dashboard para WordPress es vulnerable a la Gestión Inadecuada de Privilegios en las versiones 7.1.0 a la 9.0.2. Esto se debe a que la función 'update_settings()' acepta nombres de configuración de plugin arbitrarios sin una lista blanca de configuraciones permitidas. Esto…
AplazadaAlta (8.8)0.64%—ExactmetricsAI11/3/202617/6/2026
El plugin ExactMetrics – Google Analytics Dashboard para WordPress es vulnerable a Referencia Directa Insegura a Objeto en las versiones 8.6.0 a 9.0.2. Esto se debe a que el método 'store_settings()' en la clase 'ExactMetrics_Onboarding' acepta un parámetro 'triggered_by' proporcionado por el usuario que se utiliza en…
AplazadaMedia (4.3)0.24%—TextmetricsAI23/1/202617/6/2026
Neutralización Incorrecta de Etiquetas HTML Relacionadas con Scripts en una Página Web (XSS Básico) en Israpil Textmetrics webtexttool permite la Inyección de Código. Este problema afecta a Textmetrics: desde n/a hasta <= 3.6.3.
AplazadaBaja (2.7)0.34%—VictoriametricsAI25/11/202517/6/2026
VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits…
AnalizadaCrítica (10)0.74%—Radiometrics Vizair4/11/202517/6/2026
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally,…
AnalizadaCrítica (10)0.77%—Radiometrics Vizair4/11/202517/6/2026
Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and…
AnalizadaCrítica (10)0.66%—Radiometrics Vizair4/11/202517/6/2026
Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially…
AplazadaAlta (8.8)0.42%—SEO MetricsAI2/8/202517/6/2026
El complemento SEO Metrics para WordPress es vulnerable a la escalada de privilegios debido a la falta de comprobaciones de autorización tanto en el controlador AJAX seo_metrics_handle_connect_button_click() como en la función seo_metrics_handle_custom_endpoint() en las versiones 1.0.5 a 1.0.15. Dado que la acción…
AplazadaMedia (6)0.22%—Akka-cluster-metricsAI28/6/202517/6/2026
Desde Akka hasta 2.10.6, akka-cluster-metrics utiliza la serialización de Java para las métricas del clúster.
ModificadaMedia (4.8)0.23%—Textmetrics22/4/202517/6/2026
La vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') en Israpil Textmetrics permite XSS almacenado. Este problema afecta a Textmetrics desde n/d hasta la versión 3.6.2.
AplazadaMedia (5.4)0.53%—TextmetricsAI27/3/202517/6/2026
La vulnerabilidad de falta de autorización en Israpil Textmetrics permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Textmetrics desde n/d hasta la versión 3.6.1.
AplazadaMedia (5.4)0.31%—Exactmetrics Google Analytics Dashboard FOR WPAI24/1/202517/6/2026
Vulnerabilidad de falta de autorización en ExactMetrics ExactMetrics permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a ExactMetrics: desde n/a hasta 8.1.0.
AnalizadaAlta (7.5)0.33%—Loway Queuemetrics8/9/202417/6/2026
Loway - CWE-204: Discrepancia de respuesta observable
Orbitaley — Vulnerabilidades