Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.56% | — | Avation Light Engine PROAI | 3/2/2026 | 17/6/2026 | Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. | |
| Aplazada | Media (4.6) | 0.48% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine OputilsAI | 30/1/2026 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details. | |
| Aplazada | Alta (7.2) | 0.74% | — | AI EngineAI | 28/1/2026 | 17/6/2026 | The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.21% | — | AI EngineAI | 27/1/2026 | 17/6/2026 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web… | |
| Analizada | Alta (7.5) | 0.21% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Analizada | Crítica (9.8) | 0.32% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Analizada | Alta (7.5) | 0.29% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Aplazada | Media (6.5) | 0.24% | — | Is-daouda Is-engineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4. | |
| Aplazada | Alta (7.5) | 0.30% | — | IS Daouda IS EngineAI | 27/1/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4. | |
| Aplazada | Crítica (9.3) | 0.36% | — | Turanszkij Wicked EngineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C. This issue affects WickedEngine: through 0.71.727. | |
| Aplazada | Media (5.1) | 0.13% | — | Turanszkij Wicked EngineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Gaijin Entertainment Dagor EngineAI | 27/1/2026 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through dagor_2025_01_15. | |
| Analizada | Alta (7.2) | 0.30% | — | Expressionengine | 26/1/2026 | 17/6/2026 | SQL Injection vulnerability in the Structure for Admin authenticated user | |
| Aplazada | Alta (7.1) | 0.29% | 💥 PoC | Crocoblock JetengineAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7. | |
| Analizada | Crítica (9.3) | 1.1% | — | Hasura Graphql Engine | 21/1/2026 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient… | |
| Analizada | Media (5.5) | 0.60% | 💥 PoC | Zohocorp Manageengine Admanager Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Analizada | Crítica (9.1) | 1.6% | — | Zohocorp Manageengine Adselfservice Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations. | |
| Aplazada | Media (4.9) | 6.2% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 7/1/2026 | 17/6/2026 | This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the… | |
| Aplazada | Media (4.3) | 0.19% | — | Crocoblock JetengineAI | 7/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1. | |
| Aplazada | Media (6.5) | 0.19% | — | Codetipi Valenti-engineAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti Engine valenti-engine allows DOM-Based XSS.This issue affects Valenti Engine: from n/a through <= 1.0.3. | |
| Analizada | Alta (7.5) | 0.41% | 💥 PoC | Inmusicbrands Engine DJ Desktop | 30/12/2025 | 17/6/2026 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | |
| Analizada | Media (6.9) | 0.38% | — | Hasura Graphql Engine | 22/12/2025 | 17/6/2026 | Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially… |