Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.46%—AI EngineAI15/6/202617/6/2026
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
AplazadaAlta (8.8)0.56%—Wpengine Faust.jsAI15/6/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.
AplazadaBaja (2.1)0.20%—Hcengineering Huly PlatformAI15/6/202624/7/2026
A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The attack may be launched remotely. The…
AplazadaBaja (2.1)0.21%—Hcengineering Huly PlatformAI15/6/202624/7/2026
A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (7.2)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path,…
AnalizadaMedia (6.1)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on…
AnalizadaAlta (7.5)0.56%—Tdengine10/6/202623/7/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the…
AplazadaMedia (4.9)0.60%—Expressionengine Quiz AND Survey MasterAI6/6/202623/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
Pendiente de análisisAlta (7.2)0.17%💥 PoCMobyAIDocker EngineAI5/6/20269/9/2026
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the…
Pendiente de análisisMedia (6.1)0.28%—Northern.tech Cfengine EnterpriseAI2/6/202622/7/2026
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
AplazadaAlta (7.1)0.25%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.
Pendiente de análisisAlta (8.7)0.35%—3DS Delmia Service Process EngineerAI1/6/202622/7/2026
A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary script code in user's browser session.
Pendiente de análisisAlta (7.8)0.83%💥 PoCRaynet Rayventory Scan EngineAI27/5/202617/6/2026
Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upload, inventory, and oracle options.
AnalizadaAlta (7.2)0.50%—IBM Engineering Lifecycle Management26/5/202624/7/2026
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
AnalizadaCrítica (9.8)0.59%—IBM Engineering Lifecycle Management26/5/202624/7/2026
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.
AnalizadaAlta (7.1)0.41%—IBM Engineering Lifecycle Management26/5/202624/7/2026
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI25/5/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.
Pendiente de análisisAlta (8.4)4.0%—Zohocorp Manageengine Adselfservice PlusAIZohocorp Manageengine Datasecurity PlusAIZohocorp Manageengine Recoverymanager PlusAI21/5/202623/7/2026
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
AnalizadaAlta (8.1)0.71%💥 PoCMicrosoft Malware Protection Engine20/5/202623/7/2026
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.44%⚠ Explotación activa💥 PoCMicrosoft Malware Protection Engine20/5/202624/7/2026
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.8)0.44%—AI EngineAI17/5/202617/6/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without…
AnalizadaAlta (7.3)0.92%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
AnalizadaMedia (5.3)0.21%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
AnalizadaMedia (6.1)0.17%—Northern.tech Cfengine14/5/202617/6/2026
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
Pendiente de análisisCrítica (9.8)0.39%💥 PoCRayventory Scan EngineAI8/5/202617/6/2026
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.