Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Rtcamp RtmediaAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |
| Aplazada | Media (6.8) | 0.43% | 💥 PoC | Easy Media ReplaceAI | 19/8/2026 | 26/8/2026 | The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who… | |
| Aplazada | Media (6.5) | 0.22% | — | Davidlingren Media Library AssistantAI | 18/8/2026 | 21/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39. | |
| Aplazada | Alta (8.6) | 0.58% | — | Mediawiki MapsAI | 18/8/2026 | 9/9/2026 | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Marketing Encyclopedia System | 18/8/2026 | 2/9/2026 | Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing… | |
| Analizada | Media (5.5) | 0.18% | 💥 PoC | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.67% | — | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.73% | 💥 PoC | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. | |
| Analizada | Crítica (9.1) | 0.74% | — | Nvidia Triton Inference Server | 18/8/2026 | 2/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure. | |
| Pendiente de análisis | Alta (7.1) | 0.30% | — | Nvidia NvosAI | 18/8/2026 | 20/8/2026 | NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not… | |
| Analizada | Alta (8.8) | 0.31% | — | Nvidia Cumulus Linux | 18/8/2026 | 2/9/2026 | NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution. | |
| Analizada | Alta (7.8) | 0.13% | — | Nvidia Cumulus Linux | 18/8/2026 | 2/9/2026 | NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Alta (7.2) | 0.42% | — | Platnosci Online Blue MediaAI | 16/8/2026 | 20/8/2026 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by… | |
| Aplazada | Media (6.4) | 0.41% | — | Fastlinemedia Beaver BuilderAI | 15/8/2026 | 20/8/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Pendiente de análisis | Media (4.3) | 0.25% | — | Opennms MeridianAIOpennms HorizonAI | 13/8/2026 | 8/9/2026 | An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A… | |
| Pendiente de análisis | Media (5.4) | 0.29% | — | Opennms MeridianAIOpennms HorizonAI | 13/8/2026 | 8/9/2026 | A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access… | |
| Aplazada | Media (5.3) | 0.28% | — | Open5gsAIFreediameterAI | 12/8/2026 | 29/9/2026 | A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely. | |
| En análisis | Media (5.4) | 0.12% | — | Intel Battery Life Diagnostic ToolAI | 11/8/2026 | 12/8/2026 | Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Baja (1.9) | 0.17% | — | Bazylhorsey Obsidian-mcp-serverAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report… | |
| Pendiente de análisis | Alta (7.7) | 0.40% | — | Plesk ObsidianAI | 7/8/2026 | 3/9/2026 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database. |