Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.27%—Cisco Identity Services Engine6/5/202629/6/2026
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this…
AnalizadaMedia (4.3)0.22%—Cisco Identity Services Engine6/5/20261/7/2026
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on…
ModificadaMedia (5.5)0.20%—Redhat Multicluster Engine FOR Kubernetes30/4/20265/9/2026
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials…
AplazadaMedia (5.5)0.59%—Eghuzefa Engineer-your-dataAI28/4/202624/7/2026
A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/server.py. The manipulation of the argument WORKSPACE_PATH leads to path traversal. The attack may be initiated remotely. The exploit is publicly…
ModificadaMedia (6.3)0.46%—Socialengine23/4/202617/6/2026
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary…
ModificadaCrítica (9.3)1.0%—Socialengine23/4/202617/6/2026
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability to read…
AnalizadaCrítica (9.1)0.76%—Volcengine Openviking17/4/202614/7/2026
OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke privileged bot-control…
AnalizadaAlta (8.2)2.1%—Zohocorp Manageengine Log36016/4/202611/8/2026
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
Pendiente de análisisAlta (8.1)2.6%—Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI16/4/202617/6/2026
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
AnalizadaCrítica (9.9)5.6%—Cisco Identity Services Engine15/4/202629/6/2026
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to…
AnalizadaCrítica (9.9)6.0%💥 PoCCisco Identity Services Engine15/4/20268/7/2026
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to…
AnalizadaMedia (4.8)0.17%—Cisco Identity Services Engine15/4/20262/7/2026
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management…
AnalizadaMedia (4.9)6.5%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector15/4/202625/9/2026
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper…
AnalizadaCrítica (9.9)10%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine15/4/202625/9/2026
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient…
AnalizadaMedia (6)0.50%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector15/4/202625/9/2026
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This…
AplazadaAlta (7.5)0.46%—Crocoblock JetengineAI14/4/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of…
AnalizadaCrítica (9.8)0.50%—Janobe Engineers Online Portal10/4/202617/6/2026
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
AplazadaMedia (4.3)0.23%—Jordymeow AI Engine PROAI8/4/202624/7/2026
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.
AnalizadaMedia (6.9)0.38%—Volcengine Openviking7/4/202614/7/2026
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to…
AnalizadaAlta (7.7)0.98%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users…
AnalizadaAlta (8.7)0.74%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and…
AnalizadaAlta (8.7)0.98%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,…
AplazadaBaja (2.1)0.34%—Hcengineering Huly PlatformAI6/4/202624/7/2026
A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used.…
AplazadaBaja (2.9)0.39%—Hcengineering Huly PlatformAI6/4/202624/7/2026
A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded…
AplazadaMedia (6.4)0.16%—Wptravelengine WP Travel EngineAI4/4/202624/7/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…