Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.2) | 0.17% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle E-business Suite Secure Enterprise Search | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.3) | 0.41% | — | Mcp-webresearchAI | 21/7/2026 | 23/7/2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory… | |
| Analizada | Media (6.5) | 0.32% | — | Elasticsearch | 21/7/2026 | 26/8/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest… | |
| Aplazada | Crítica (10) | 0.75% | — | Prestashop PS FacetedsearchAI | 17/7/2026 | 23/7/2026 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal… | |
| Aplazada | Alta (7.5) | 0.51% | — | Themehunk Advance Product SearchAI | 16/7/2026 | 18/7/2026 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Pendiente de análisis | Crítica (9.8) | 0.89% | — | Open Source GPT Researcher GPT ResearcherAI | 15/7/2026 | 6/10/2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Strands Agents ToolsAIElasticsearchAI | 15/7/2026 | 15/7/2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the… | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Bing Search | 14/7/2026 | 24/7/2026 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JetsearchAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Eyecix JobsearchAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9. | |
| Aplazada | Media (6.4) | 0.26% | — | Buddyholis TablesearchAI | 10/7/2026 | 10/7/2026 | The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Baja (2) | 0.36% | — | Nousresearch Hermes-agentAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The… | |
| Pendiente de análisis | Alta (7.1) | 0.57% | — | Amazon Research AND Engineering StudioAI | 7/7/2026 | 8/7/2026 | AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read… | |
| Aplazada | Baja (2.1) | 0.48% | — | Nousresearch Hermes-agentAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.2) | 1.4% | 💥 Exploit | Circl Cve-searchAI | 5/7/2026 | 6/7/2026 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose… | |
| Aplazada | Media (5.5) | 0.77% | 💥 PoC | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.9) | 0.55% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 7/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may… |