Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202620/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
AnalizadaMedia (5.4)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
AnalizadaMedia (6.9)0.78%—Volcengine Openviking1/4/202614/7/2026
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass…
Pendiente de análisisAlta (7.6)0.80%—Agentic-context-engineAI31/3/202625/7/2026
A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the…
AnalizadaAlta (7.8)0.16%💥 PoCDocker Engine31/3/202617/6/2026
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
ModificadaAlta (8.1)0.51%—Docker Engine31/3/20269/9/2026
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that…
AplazadaMedia (5.5)0.53%—Promptengineer LocalgptAI28/3/202617/6/2026
A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the file rag_system/api_server.py of the component Web Interface. Performing a manipulation results in information disclosure. It is possible to initiate the attack remotely.…
AplazadaMedia (5.5)0.52%—Promptengineer LocalgptAI28/3/202617/6/2026
A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file backend/server.py of the component LLM Prompt Handler. Such manipulation leads to injection. The attack may be performed from remote. The…
AplazadaMedia (5.5)0.47%—Promptengineer LocalgptAI28/3/202617/6/2026
A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the file backend/server.py. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may be used.…
AplazadaMedia (6.9)0.65%💥 PoCPromptengineer LocalgptAI28/3/202617/6/2026
A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the function LocalGPTHandler of the file backend/server.py of the component API Endpoint. The manipulation of the argument BaseHTTPRequestHandler results in missing authentication. The attack can be…
AplazadaCrítica (9.1)0.50%—Jordymeow Photo EngineAI25/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.
AplazadaAlta (7.5)0.54%—Crocoblock JetengineAI24/3/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks)…
AnalizadaMedia (5.1)0.24%—Wowza Streaming Engine16/3/202617/6/2026
Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost,…
AnalizadaMedia (6.9)0.16%—Wowza Streaming Engine16/3/202617/6/2026
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin…
AnalizadaAlta (8.7)0.21%—Wowza Streaming Engine16/3/202617/6/2026
Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true'…
AnalizadaAlta (8.5)0.21%—Wowza Streaming Engine16/3/202617/6/2026
Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine…
AplazadaMedia (5.3)0.29%—Wptravelengine Travel-bookingAI13/3/202617/6/2026
Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Booking: from n/a through <= 1.3.9.
AplazadaAlta (8.8)0.52%—Crocoblock JetengineAI13/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.
AplazadaBaja (2.1)0.39%—Autohomecorp FrostmourneAIOracle Nashorn Javascript EngineAI12/3/202617/6/2026
A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has…