Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.51%—WP Fast Total SearchAI28/7/202628/7/2026
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaMedia (5.2)0.34%—Tp-link TL Wr845nAITp-link TL Wr850nAITp-link TL Wr902acAITp-link Archer C20AI+127/7/202611/8/2026
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.…
AplazadaBaja (1.3)0.36%—Nousresearch Hermes-agentAI26/7/202627/7/2026
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.…
AnalizadaAlta (8.8)0.55%—Microsoft Azure AI Search24/7/202629/7/2026
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202627/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by…
AplazadaMedia (5.1)0.24%—GFI ArchiverAI23/7/202623/7/2026
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is…
AplazadaMedia (5.3)0.29%—WP Fast Total SearchAI23/7/202623/7/2026
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
AplazadaCrítica (9.8)1.1%—Conexware Power ArchiverAI22/7/202624/7/2026
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
AplazadaAlta (7.8)0.19%—IzarcAIRarlab UnrarAI22/7/20261/10/2026
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
AnalizadaMedia (6.5)0.42%—Elasticsearch22/7/20263/8/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource exhaustion persists…
AnalizadaMedia (6.5)0.42%—Elasticsearch21/7/20263/8/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation…
AnalizadaAlta (8.1)0.36%—Oracle E-business Suite Secure Enterprise Search21/7/202617/8/2026
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaAlta (7.1)0.39%—Oracle Commerce Guided Search Platform Services21/7/20263/8/2026
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform…
AnalizadaAlta (7.4)0.34%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…
AnalizadaAlta (8.1)0.39%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AnalizadaAlta (7.1)0.16%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
AnalizadaCrítica (9.8)0.51%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (8.1)0.42%—Oracle Commerce Experience ManagerOracle Commerce Guided Search21/7/202624/7/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…