Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

21.612 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)0.26%—Tanium Threat ResponseAI16/9/202618/9/2026
Tanium addressed an improper access controls vulnerability in Threat Response.
Pendiente de análisisAlta (8.8)0.43%—Tanium Threat ResponseAI16/9/202618/9/2026
Tanium addressed a SQL injection vulnerability in Threat Response.
Pendiente de análisisMedia (6.5)0.38%—Tanium DiscoverAI16/9/202618/9/2026
Tanium addressed an information disclosure vulnerability in Discover.
Pendiente de análisisBaja (3.8)0.26%—Tanium Threat ResponseAI16/9/202618/9/2026
Tanium addressed an improper access controls vulnerability in Threat Response.
Pendiente de análisisAlta (7.2)0.45%—Tanium AssetAI16/9/202618/9/2026
Tanium addressed a SQL injection vulnerability in Asset.
Pendiente de análisisAlta (7.2)0.45%—Tanium AssetAI16/9/202618/9/2026
Tanium addressed a SQL injection vulnerability in Asset.
AnalizadaBaja (2.3)0.44%—Apache Nifi16/9/202621/9/2026
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups…
AnalizadaMedia (5.9)0.48%—Apache Nifi16/9/202621/9/2026
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase operations. Framework authorization for these methods was limited to read and…
AnalizadaBaja (0.5)0.56%—Apache Nifi16/9/202621/9/2026
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset and Secret references, but framework…
AnalizadaAlta (7.5)0.62%—Apache Nifi16/9/202621/9/2026
Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject…
AplazadaMedia (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI16/9/202616/9/2026
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is…
AplazadaMedia (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI16/9/202616/9/2026
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may…
AplazadaMedia (5.5)0.56%—Code-projects Matrimonial SystemAI16/9/202616/9/2026
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated…
Pendiente de análisisAlta (8.8)0.16%—Avast Sandbox Minifilter DriverAI16/9/202617/9/2026
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened…
AplazadaMedia (5.3)0.30%—Adenion Blog2socialAI16/9/202624/9/2026
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id…
Pendiente de análisisAlta (8)0.41%—Jenkins WarningsAIJenkinsAI16/9/202618/9/2026
Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS)…
AplazadaMedia (5.3)0.28%—Adenion Blog2socialAI16/9/202624/9/2026
Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without…
AplazadaMedia (5.3)0.28%—Adenion Blog2socialAI16/9/202624/9/2026
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to…
AplazadaAlta (7)0.09%—Duoxme ApplicationAIVEO Wifi MonitorAIVEO XS Wifi MonitorAI16/9/202618/9/2026
Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network…
AplazadaMedia (5.7)0.32%—S-sols Seraphinite AcceleratorAI16/9/202617/9/2026
The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught error on every subsequent admin page load, making the entire admin area…
AplazadaMedia (5.3)0.39%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's…
AplazadaAlta (8.6)0.45%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (7.1)0.36%—Nr255-vAIL2tpdAINissc IpsecAI15/9/202616/9/2026
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material.
Pendiente de análisisMedia (6.5)0.37%—Devolutions Powershell UniversalAI15/9/202616/9/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
AplazadaMedia (6.9)0.38%—Miniorange JWT Authentication FOR WP Rest ApisAI15/9/202624/9/2026
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.…