Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.27% | — | Friendsofflarum OauthAI | 25/9/2026 | 30/9/2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When… | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | Oracle Sales OfflineAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle Sales OfflineAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the… | |
| Analizada | Crítica (9.8) | 0.80% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. | |
| Analizada | Crítica (9.8) | 0.92% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (5.3) | 0.36% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. | |
| Analizada | Media (5.3) | 0.46% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address. | |
| Analizada | Alta (8) | 0.38% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Analizada | Alta (8.3) | 0.39% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Sales Offline | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… | |
| Aplazada | Alta (8.8) | 1.1% | — | Offload AI Optimize With Cloudflare ImagesAI | 18/6/2026 | 18/6/2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the… | |
| Aplazada | Media (6.5) | 0.19% | — | OfflineimapAI | 8/6/2026 | 23/7/2026 | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext. | |
| Aplazada | Alta (7.3) | 0.53% | — | Offline Hospital Management SystemAI | 18/5/2026 | 17/6/2026 | Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system… | |
| Aplazada | Media (6.7) | 0.33% | — | Surfoffline ProfessionalAI | 12/2/2026 | 17/6/2026 | SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of… | |
| Aplazada | Media (6.5) | 0.25% | — | Anton Vanyukov Offload AI Optimize With Cloudflare ImagesAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5. | |
| Aplazada | Media (4.3) | 0.24% | — | Freehtmldesigns Site OfflineAI | 28/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in chandrashekharsahu Site Offline site-offline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Offline: from n/a through <= 1.5.7. | |
| Analizada | Alta (8.1) | 0.22% | — | Webgarh Offload Videos | 15/5/2025 | 17/6/2026 | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack | |
| Aplazada | Alta (7.1) | 0.24% | — | Promact WP Azure OffloadAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Graphics Offline Compiler FOR OpenclAIIntel Graphics DriverAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, graphics driver 31.0.101.5445 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Leopardplugins Leopard Offload MediaAI | 9/11/2024 | 17/6/2026 | The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.36% | — | Nouthemes Leopard - Wordpress Offload MediaAI | 19/8/2024 | 17/6/2026 | Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36. | |
| Modificada | Media (4.8) | 0.39% | — | Freehtmldesigns Site Offline | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6. | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle Sales Offline | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of… |