Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

6557 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.15%—HCL Hive Keycloak IAMAI24/8/20267/10/2026
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
AplazadaCrítica (9.1)0.50%—Punk Oauth2 ServerAI22/8/202626/8/2026
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in…
Pendiente de análisisMedia (6.2)0.52%—Opensearch Dashboards-observabilityAI21/8/202627/8/2026
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web…
AplazadaBaja (3.7)0.26%—Limitloginattempts Limit Login Attempts ReloadedAI21/8/202626/8/2026
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
AplazadaAlta (8.1)0.54%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
AplazadaBaja (3.5)0.24%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
Pendiente de análisisAlta (8.7)0.66%—Opensearch DashboardsAI20/8/202625/8/2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code…
AplazadaMedia (5.3)0.44%💥 PoCPhoca DownloadAI20/8/202626/8/2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
AplazadaMedia (5.7)0.50%—Punk Oauth2AI20/8/202628/8/2026
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow…
Pendiente de análisisMedia (4.3)0.19%—Zoom APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are…
Pendiente de análisisMedia (4.3)0.12%—Venafi APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user…
Pendiente de análisisMedia (4.3)0.19%—Attack Analyzer Connector FOR Splunk SoarAI19/8/202620/8/2026
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in…
Pendiente de análisisMedia (4.3)0.21%—RSA Securid Authentication ManagerAISplunk SoarAI19/8/202620/8/2026
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in…
Pendiente de análisisMedia (4.3)0.19%—MS Graph FOR Active Directory APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.…
Pendiente de análisisMedia (4.3)0.19%—Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in…
Pendiente de análisisMedia (4.3)0.19%—Cisco Webex APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The…
Pendiente de análisisMedia (4.3)0.19%—Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user…
Pendiente de análisisMedia (4.3)0.19%—Splunk SoarAIMicrosoft Azure AD GraphAI19/8/202620/8/2026
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information…
Pendiente de análisisMedia (4.3)0.19%—AWS IAM APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext in the user interface. The information…
Pendiente de análisisMedia (5)0.29%—Splunk AD LdapAISplunk SoarAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an…
Pendiente de análisisMedia (4.3)0.29%—Splunk SoarAISplunk AD LdapAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR…
Pendiente de análisisMedia (5.4)0.25%—Splunk Soar AD LdapAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory…
Pendiente de análisisBaja (2.7)0.28%—Splunk FireampAISplunk SoarAI19/8/202620/8/2026
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the…
AnalizadaMedia (4.3)0.27%—Splunk Soar19/8/202621/8/2026
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because Splunk SOAR does not enforce role-based…
AnalizadaBaja (2.7)0.35%—Splunk Soar19/8/202621/8/2026
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and…