Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.18% | — | Volcengine OpenvikingAI | 28/6/2026 | 29/6/2026 | A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data… | |
| Pendiente de análisis | Crítica (9.8) | 0.93% | — | Genshi Template EngineAI | 26/6/2026 | 26/6/2026 | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 26/6/2026 | 29/6/2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. | |
| Aplazada | Alta (8.7) | 0.55% | — | Winstone Servlet EngineAI | 25/6/2026 | 25/6/2026 | Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot. Attackers can traverse outside the webroot… | |
| Aplazada | Alta (8.1) | 0.72% | 💥 PoC | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Pendiente de análisis | Crítica (9) | 2.5% | 💥 PoC | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 23/6/2026 | 24/6/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Pendiente de análisis | Media (6.9) | 0.51% | — | Google APP EngineAIGoogle Cloud ConsoleAI | 22/6/2026 | 22/6/2026 | A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and… | |
| Analizada | Media (6.1) | 0.25% | — | IBM Engineering Workflow Management | 22/6/2026 | 1/10/2026 | IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Engineering Workflow Management | 22/6/2026 | 6/10/2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. | |
| Modificada | Alta (7) | 0.37% | 💥 PoC | Microsoft Malware Protection Engine | 16/6/2026 | 12/8/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wptravelengine WP Travel EngineAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wptravelengine WP Travel EngineAI | 15/6/2026 | 17/6/2026 | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. |