Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetsearchAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16. | |
| Analizada | Media (6.5) | 0.32% | — | Learningcircuit Local Deep Research | 23/12/2025 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to… | |
| Aplazada | Media (5.4) | 0.28% | — | FibosearchAI | 20/12/2025 | 17/6/2026 | The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.27% | — | Arcsearch FOR IOSAI | 19/12/2025 | 17/6/2026 | ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk. | |
| Aplazada | Alta (7.4) | 0.23% | — | ArcsearchAI | 19/12/2025 | 17/6/2026 | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Analizada | Media (4.9) | 0.38% | — | Elasticsearch | 18/12/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request. | |
| Analizada | Media (5.3) | 0.41% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat. | |
| Analizada | Media (6.5) | 0.25% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages. | |
| Analizada | Media (6.5) | 0.46% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number. | |
| Analizada | Media (6.5) | 0.32% | — | Elasticsearch | 18/12/2025 | 30/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data. | |
| Aplazada | Media (4.3) | 0.22% | — | Creativemindssolutions CM ON Demand Search AND ReplaceAI | 16/12/2025 | 7/10/2026 | Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.5. | |
| Analizada | Alta (7.4) | 0.19% | — | Elasticsearch | 15/12/2025 | 7/10/2026 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority. | |
| Aplazada | Media (6.4) | 0.28% | — | Samsung Search WidgetAI | 12/12/2025 | 7/10/2026 | The BUKAZU Search widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode' parameter of the 'bukazu_search' shortcode in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.32% | — | Ivorysearch Ivory SearchAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Vinod Dalvi Ivory Search add-search-to-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ivory Search: from n/a through <= 5.5.12. | |
| Aplazada | Media (5.5) | 0.31% | — | SAP Enterprise Search FOR AbapAI | 9/12/2025 | 7/10/2026 | Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on application's availability. | |
| Aplazada | Media (4.3) | 0.23% | — | Search Filters MerchandisingAI | 6/12/2025 | 17/6/2026 | The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcis_save_email' endpoint in all versions up to, and including, 3.0.67. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (4.3) | 0.20% | — | Search-guard FLXAI | 1/12/2025 | 17/6/2026 | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges. | |
| Modificada | Alta (8.3) | 0.51% | — | Amazon Opensearch | 25/11/2025 | 17/6/2026 | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4. | |
| Aplazada | Media (4.3) | 0.18% | — | Search ExcludeAI | 25/11/2025 | 17/6/2026 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all versions up to, and including, 2.5.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify… | |
| Aplazada | Media (6) | 0.28% | — | Search-guard FLXAI | 14/11/2025 | 7/10/2026 | In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Online JOB Search Engine | 10/11/2025 | 7/10/2026 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.3) | 0.31% | — | Amazon Research AND Engineering StudioAI | 6/11/2025 | 7/10/2026 | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Elated-themes Search AND GOAI | 6/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows Password Recovery Exploitation.This issue affects Search & Go: from n/a through <= 2.7. | |
| Aplazada | Media (5.5) | 0.25% | — | Wpdreams Ajax Search LiteAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3. | |
| Aplazada | Alta (7.5) | 0.46% | — | Premmerce Product Search FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows PHP Local File Inclusion.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4. |