Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.56%—Avation Light Engine PROAI3/2/202617/6/2026
Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
AplazadaMedia (4.6)0.48%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine OputilsAI30/1/202617/6/2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
AplazadaAlta (7.2)0.74%—AI EngineAI28/1/202617/6/2026
The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.21%—AI EngineAI27/1/202617/6/2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web…
AnalizadaAlta (7.5)0.21%—Ixray-team Ix-ray Engine 1.627/1/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
AnalizadaCrítica (9.8)0.32%—Ixray-team Ix-ray Engine 1.627/1/202617/6/2026
Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
AnalizadaAlta (7.5)0.29%—Ixray-team Ix-ray Engine 1.627/1/202617/6/2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
AplazadaMedia (6.5)0.24%—Is-daouda Is-engineAI27/1/202617/6/2026
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.
AplazadaAlta (7.5)0.30%—IS Daouda IS EngineAI27/1/202617/6/2026
Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.
AplazadaCrítica (9.3)0.36%—Turanszkij Wicked EngineAI27/1/202617/6/2026
Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C. This issue affects WickedEngine: through 0.71.727.
AplazadaMedia (5.1)0.13%—Turanszkij Wicked EngineAI27/1/202617/6/2026
Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705.
AplazadaCrítica (9.3)0.29%—Gaijin Entertainment Dagor EngineAI27/1/202617/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through dagor_2025_01_15.
AnalizadaAlta (7.2)0.30%—Expressionengine26/1/202617/6/2026
SQL Injection vulnerability in the Structure for Admin authenticated user
AplazadaAlta (7.1)0.29%💥 PoCCrocoblock JetengineAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.
AnalizadaCrítica (9.3)1.1%—Hasura Graphql Engine21/1/202617/6/2026
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL's COPY FROM PROGRAM…
AnalizadaMedia (4.8)0.27%—Cisco Identity Services Engine15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based…
AnalizadaMedia (4.8)0.27%—Cisco Identity Services Engine15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient…
AnalizadaMedia (5.5)0.60%💥 PoCZohocorp Manageengine Admanager Plus13/1/202617/6/2026
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
AnalizadaAlta (8.1)0.80%—Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO13/1/202617/6/2026
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
AnalizadaCrítica (9.1)1.6%—Zohocorp Manageengine Adselfservice Plus13/1/202617/6/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
AplazadaMedia (4.9)6.2%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI7/1/202617/6/2026
This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the…
AplazadaMedia (4.3)0.19%—Crocoblock JetengineAI7/1/20267/10/2026
Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.
AplazadaMedia (6.5)0.19%—Codetipi Valenti-engineAI31/12/202523/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti Engine valenti-engine allows DOM-Based XSS.This issue affects Valenti Engine: from n/a through <= 1.0.3.
AnalizadaAlta (7.5)0.41%💥 PoCInmusicbrands Engine DJ Desktop30/12/202517/6/2026
inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.
AnalizadaMedia (6.9)0.38%—Hasura Graphql Engine22/12/202517/6/2026
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially…