Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.18%—Volcengine OpenvikingAI28/6/202629/6/2026
A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data…
Pendiente de análisisCrítica (9.8)0.93%—Genshi Template EngineAI26/6/202626/6/2026
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI26/6/202629/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
AplazadaAlta (8.7)0.55%—Winstone Servlet EngineAI25/6/202625/6/2026
Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot. Attackers can traverse outside the webroot…
AplazadaAlta (8.1)0.72%💥 PoCVmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI23/6/202625/6/2026
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
Pendiente de análisisCrítica (9)2.5%💥 PoCManageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI23/6/202624/6/2026
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
Pendiente de análisisMedia (6.9)0.51%—Google APP EngineAIGoogle Cloud ConsoleAI22/6/202622/6/2026
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and…
AnalizadaMedia (6.1)0.25%—IBM Engineering Workflow Management22/6/20261/10/2026
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the…
AnalizadaMedia (5.4)0.23%—IBM Engineering Workflow Management22/6/20266/10/2026
IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to…
AnalizadaAlta (7.5)0.50%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector17/6/202625/9/2026
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected…
AnalizadaCrítica (9.1)8.9%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector17/6/202625/9/2026
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of…
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
AplazadaAlta (7.5)0.32%—Crocoblock JetengineAI17/6/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202628/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
ModificadaAlta (7)0.37%💥 PoCMicrosoft Malware Protection Engine16/6/202612/8/2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.
AplazadaCrítica (9.8)0.56%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
AplazadaAlta (7.5)0.37%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.