Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | WP Fast Total SearchAI | 28/7/2026 | 28/7/2026 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (5.2) | 0.34% | — | Tp-link TL Wr845nAITp-link TL Wr850nAITp-link TL Wr902acAITp-link Archer C20AI+1 | 27/7/2026 | 11/8/2026 | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.… | |
| Aplazada | Baja (1.3) | 0.36% | — | Nousresearch Hermes-agentAI | 26/7/2026 | 27/7/2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.… | |
| Analizada | Alta (8.8) | 0.55% | — | Microsoft Azure AI Search | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 27/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by… | |
| Aplazada | Media (5.1) | 0.24% | — | GFI ArchiverAI | 23/7/2026 | 23/7/2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is… | |
| Aplazada | Media (5.3) | 0.29% | — | WP Fast Total SearchAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Conexware Power ArchiverAI | 22/7/2026 | 24/7/2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | |
| Aplazada | Alta (7.8) | 0.19% | — | IzarcAIRarlab UnrarAI | 22/7/2026 | 1/10/2026 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 22/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource exhaustion persists… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 3/8/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle E-business Suite Secure Enterprise Search | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.1) | 0.39% | — | Oracle Commerce Guided Search Platform Services | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.1) | 0.16% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.1) | 0.42% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 21/7/2026 | 24/7/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |