Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8750 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.38% | — | FreescoutAI | 20/7/2026 | 21/7/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or… | |
| Aplazada | Alta (7.5) | 0.63% | — | FreescoutAI | 20/7/2026 | 21/7/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is… | |
| Aplazada | Media (6.5) | 0.34% | — | FreescoutAI | 20/7/2026 | 21/7/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (`opened_at` timestamp)… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.19% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.46% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (8.8) | 0.42% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Cisco Catalyst 1719 AentrAI | 14/7/2026 | 14/7/2026 | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. | |
| Pendiente de análisis | Media (6) | 0.33% | — | Cisco HyperflexAI | 14/7/2026 | 15/7/2026 | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service. | |
| Aplazada | Media (6.3) | 0.39% | — | Skillable ScormAI | 13/7/2026 | 16/7/2026 | The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab… | |
| Aplazada | Alta (8.8) | 0.23% | — | Purethemes Workscout-coreAI | 13/7/2026 | 13/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08. | |
| Aplazada | Alta (7.5) | 0.38% | — | EscortwpAI | 10/7/2026 | 10/7/2026 | The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that covertly transmits the site URL, administrator email address, and license… | |
| Analizada | Media (5.3) | 0.55% | — | Discourse | 9/7/2026 | 13/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2,… | |
| Analizada | Alta (7.4) | 0.41% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript when default Content Security Policy… | |
| Analizada | Crítica (9) | 0.73% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is… | |
| Analizada | Media (5.4) | 0.41% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This issue is fixed in versions… | |
| Analizada | Media (6.5) | 0.30% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holder to publish validly signed forged… | |
| Analizada | Media (6.3) | 0.51% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized users through category and group… | |
| Analizada | Media (6.5) | 0.51% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. | |
| Analizada | Media (6.3) | 0.63% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and… | |
| Analizada | Media (4.3) | 0.50% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event invitee list. This issue is fixed in… | |
| Analizada | Alta (7.1) | 0.46% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in… |