Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.33% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams. | |
| Analizada | Media (4.3) | 0.29% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL. | |
| Analizada | Alta (7.1) | 0.24% | — | Watchguard Fireware | 30/3/2026 | 28/8/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page. | |
| Analizada | Alta (8.4) | 0.39% | — | Watchguard Fireware | 30/3/2026 | 28/8/2026 | An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the… | |
| Aplazada | Alta (7.2) | 0.53% | — | Fahadmahmood Injection GuardAI | 21/3/2026 | 17/6/2026 | The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. This is due to insufficient input sanitization in the sanitize_ig_data() function which only sanitizes array values but not array keys, combined with… | |
| Analizada | Baja (2) | 0.51% | — | Unguardable Online Doctor Appointment System | 20/3/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection. The attack can be launched remotely. The exploit is now public and may be… | |
| Aplazada | Alta (8.1) | 0.48% | — | Themepaste Admin Safety GuardAI | 19/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6. | |
| Analizada | Media (5.5) | 0.58% | — | Unguardable Online Doctor Appointment System | 12/3/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.58% | — | Unguardable Online Doctor Appointment System | 12/3/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Crítica (9.8) | 0.78% | 💥 PoC | Adguardhome | 11/3/2026 | 17/6/2026 | AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is… | |
| Aplazada | Media (4.3) | 0.13% | — | Guardian News FeedAI | 7/3/2026 | 17/6/2026 | The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the Guardian… | |
| Modificada | Media (4.3) | 0.41% | — | Chainguard Melange | 6/3/2026 | 7/7/2026 | melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cause unbounded disk… | |
| Aplazada | Media (5.4) | 0.27% | — | Jp-secure Siteguard WP PluginAI | 5/3/2026 | 17/6/2026 | Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affects SiteGuard WP Plugin: from n/a through <= 1.7.9. | |
| Modificada | Baja (2.1) | 0.17% | — | Nozominetworks CMCNozominetworks Guardian | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML tags. If the system is configured to use the Alerted Nodes Dashboard,… | |
| Modificada | Media (6.9) | 0.45% | — | Watchguard Fireware | 3/3/2026 | 10/8/2026 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package. | |
| Modificada | Media (5.1) | 0.34% | — | Watchguard Fireware | 3/3/2026 | 10/8/2026 | A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. | |
| Analizada | Alta (8.6) | 0.70% | — | Watchguard Fireware | 3/3/2026 | 17/6/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and… | |
| Analizada | Media (6.9) | 0.40% | — | Chainguard Malcontent | 27/2/2026 | 17/6/2026 | malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent… | |
| Modificada | Alta (8.2) | 0.84% | — | Chainguard Kaniko | 27/2/2026 | 15/7/2026 | kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives using `filepath.Join(dest, cleanedName)` without enforcing that the final path stays within `dest`. A tar entry like… | |
| Analizada | Alta (8.8) | 0.55% | — | Wgportal Wireguard Portal | 26/2/2026 | 17/6/2026 | WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and… | |
| Aplazada | Crítica (9.9) | 0.45% | — | Zozothemes WiguardAI | 20/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affects Wiguard: from n/a through < 2.0.1. | |
| Aplazada | Alta (7.8) | 0.15% | — | HPE Aruba Networking Clearpass OnguardAI | 18/2/2026 | 17/6/2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges. | |
| Aplazada | Alta (7.5) | 0.37% | 💥 PoC | Guardian GryphonAI | 17/2/2026 | 5/7/2026 | An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root. | |
| Analizada | Alta (7.7) | 0.23% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.… | |
| Analizada | Baja (2) | 0.36% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow… |