Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.21% | — | Newell Brands Dymo IDAI | 5/10/2026 | 6/10/2026 | Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the… | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Newell Brands Dymo IDAI | 5/10/2026 | 6/10/2026 | Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or… | |
| Aplazada | Media (4.3) | 0.16% | — | Brandtoss WP Admin AuditAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpmudev BrandaAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | |
| Pendiente de análisis | Media (6.9) | 0.53% | — | Grandstream Gwn7660elrAI | 18/9/2026 | 22/9/2026 | Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'. Attackers can query standard MIBs over the… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Newell Brands Dymo Connect DesktopAI | 15/9/2026 | 22/9/2026 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension… | |
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand TourAI | 2/9/2026 | 2/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1. | |
| Pendiente de análisis | Crítica (9.2) | 0.57% | — | Amazon Strands Agents ToolsAI | 25/8/2026 | 26/8/2026 | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument… | |
| Pendiente de análisis | Alta (8.6) | 0.52% | — | Amazon Strands Agents ToolsAI | 6/8/2026 | 12/8/2026 | Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Amazon Strands Agents ToolsAI | 3/8/2026 | 4/8/2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue,… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Strands Agents ToolsAI | 31/7/2026 | 4/8/2026 | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to… | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 24/7/2026 | 24/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.3) | 0.27% | — | Avada Custom BrandingAI | 23/7/2026 | 23/7/2026 | Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Grand PhotographyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | |
| Aplazada | Media (4.4) | 0.31% | — | Berocket Brands FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and… | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Strands Agents ToolsAIElasticsearchAI | 15/7/2026 | 15/7/2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Themegoods Grand PhotographyAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Analizada | Media (5.4) | 0.23% | — | Ijsbrandy Siteimprove Analytics | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1. | |
| Aplazada | Alta (7.5) | 0.51% | — | Bytes Random Secure TinyAI | 26/6/2026 | 1/7/2026 | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are… | |
| Aplazada | Alta (7.5) | 0.51% | — | Bytes Random SecureAI | 26/6/2026 | 1/7/2026 | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in… | |
| Aplazada | Crítica (9.8) | 0.62% | 💥 PoC | Wpmudev BrandaAI | 20/6/2026 | 23/6/2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's… | |
| Aplazada | Alta (7.1) | 0.18% | — | Grand CAR RentalAI | 17/6/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions. | |
| Aplazada | Media (6.9) | 0.39% | — | BrandfolderAI | 15/6/2026 | 17/6/2026 | WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to… | |
| Aplazada | Alta (8.7) | 0.54% | — | HS Brand Logo SliderAI | 16/5/2026 | 17/6/2026 | HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions… |