Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.55% | — | Discourse | 9/7/2026 | 13/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2,… | |
| Analizada | Alta (7.4) | 0.41% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript when default Content Security Policy… | |
| Analizada | Crítica (9) | 0.73% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is… | |
| Analizada | Media (5.4) | 0.41% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This issue is fixed in versions… | |
| Analizada | Media (6.5) | 0.30% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holder to publish validly signed forged… | |
| Analizada | Media (6.3) | 0.51% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized users through category and group… | |
| Analizada | Media (6.5) | 0.51% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. | |
| Analizada | Media (6.3) | 0.63% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and… | |
| Analizada | Media (4.3) | 0.50% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event invitee list. This issue is fixed in… | |
| Analizada | Alta (7.1) | 0.46% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in… | |
| Analizada | Alta (8.1) | 0.60% | — | Discourse | 9/7/2026 | 14/7/2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. | |
| Analizada | Alta (7.2) | 1.9% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to… | |
| Aplazada | Alta (7.2) | 0.51% | — | Comments WpdiscuzAI | 3/7/2026 | 6/7/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | 💥 PoC | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning,… | |
| Analizada | Alta (7.5) | 0.65% | — | Cisco Catalyst CenterCisco Catalyst Center Global Manager | 1/7/2026 | 17/9/2026 | This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. | |
| Aplazada | Media (6.5) | 0.33% | — | Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. |