Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.51% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by… | |
| Aplazada | Media (6.9) | 0.47% | — | Parseplatform Parse ServerAI | 21/7/2026 | 23/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL… | |
| Aplazada | Alta (7.5) | 0.45% | — | Bpost Shipping PlatformAI | 21/7/2026 | 21/7/2026 | The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3. | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.4) | 0.46% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vimesoft INC Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Firebase StudioAIGoogle Cloud PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Aplazada | Alta (8.7) | 0.54% | — | Axelor Open PlatformAI | 16/7/2026 | 17/7/2026 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by… | |
| Analizada | Media (6.5) | 0.32% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the… | |
| Analizada | Alta (7.2) | 0.57% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to… | |
| Analizada | Alta (8.3) | 0.18% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing… | |
| Analizada | Media (4.8) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (4.6) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Aplazada | Alta (7.1) | 0.38% | — | Praisonai PlatformAI | 15/7/2026 | 18/7/2026 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | HCL Bigfix PlatformAI | 14/7/2026 | 15/7/2026 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service. | |
| Analizada | Alta (8.7) | 0.50% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 16/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the… | |
| Analizada | Crítica (9.2) | 4.4% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint.… | |
| Analizada | Media (6.3) | 0.38% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 15/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the… | |
| Analizada | Alta (8.8) | 0.51% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such… | |
| Analizada | Alta (7) | 0.27% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation… | |
| Analizada | Media (5.3) | 0.31% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 15/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output… | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… |