Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.3) | 0.37% | — | Nousresearch Hermes-agentAI | 3/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to improper handling of case sensitivity. The… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Fast Total SearchAI | 2/7/2026 | 2/7/2026 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Search Atlas SEOAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions. | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests. | |
| Analizada | Media (4.9) | 0.50% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable. | |
| Aplazada | Media (4.4) | 0.40% | — | Ivorysearch Ivory SearchAI | 27/6/2026 | 29/6/2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Themehunk Advance Product SearchAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | SearchplusAI | 24/6/2026 | 25/6/2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both… | |
| Analizada | Alta (8.8) | 0.48% | — | Joomlaboat Extra Search | 19/6/2026 | 19/8/2026 | Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | JobsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | JetsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | JobsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. | |
| Aplazada | Alta (7.4) | 0.32% | — | ARC SearchAI | 17/6/2026 | 17/6/2026 | Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing. | |
| Analizada | Alta (8.1) | 0.25% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the… | |
| Analizada | Media (6.1) | 0.16% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by… | |
| Analizada | Media (5.6) | 0.21% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 18/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a… | |
| Aplazada | Alta (8.2) | 0.37% | — | Maian SearchAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Benbusby Whoogle SearchAI | 15/6/2026 | 17/6/2026 | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request. | |
| Aplazada | Alta (8.1) | 0.75% | — | Maian SearchAIFrankenphpAI | 10/6/2026 | 17/6/2026 | FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into… | |
| Aplazada | Media (5.1) | 0.47% | — | Typo3 CMSAITypo3 Indexed SearchAI | 9/6/2026 | 23/7/2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site… | |
| Aplazada | Baja (2.1) | 0.25% | — | Zilliztech Deep-searcherAI | 7/6/2026 | 23/7/2026 | A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.14% | — | Nousresearch Hermes-agentAI | 2/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be… | |
| Aplazada | Media (5.5) | 0.37% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The… |