Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | Themehunk Advance Product SearchAI | 16/7/2026 | 18/7/2026 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Pendiente de análisis | Crítica (9.8) | 0.89% | — | Open Source GPT Researcher GPT ResearcherAI | 15/7/2026 | 6/10/2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Strands Agents ToolsAIElasticsearchAI | 15/7/2026 | 15/7/2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the… | |
| Aplazada | Alta (7.7) | 0.45% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity… | |
| Aplazada | Media (5.8) | 0.40% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP… | |
| Aplazada | Media (6.9) | 0.66% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the… | |
| Aplazada | Alta (8.3) | 0.25% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token… | |
| Aplazada | Crítica (9.1) | 0.55% | — | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go | |
| Aplazada | Alta (7.5) | 0.31% | 💥 PoC | Andreimarcu Linux-serverAI | 14/7/2026 | 15/7/2026 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Bing Search | 14/7/2026 | 24/7/2026 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.1) | 1.4% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account… | |
| Analizada | Alta (8.5) | 2.1% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges.… | |
| Analizada | Alta (8.6) | 0.84% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JetsearchAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2. | |
| Aplazada | Alta (8.8) | 0.46% | — | Marcus Events ManagerAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Eyecix JobsearchAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.40% | — | MyparcelAI | 11/7/2026 | 13/7/2026 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view and… | |
| Analizada | Media (5.4) | 0.23% | — | Ademarco UI Patterns | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. | |
| Pendiente de análisis | Baja (3.9) | 0.20% | — | LibarchiveAI | 10/7/2026 | 21/9/2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of… | |
| Aplazada | Media (6.4) | 0.26% | — | Buddyholis TablesearchAI | 10/7/2026 | 10/7/2026 | The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Baja (2) | 0.36% | — | Nousresearch Hermes-agentAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The… | |
| Pendiente de análisis | Alta (7.1) | 0.57% | — | Amazon Research AND Engineering StudioAI | 7/7/2026 | 8/7/2026 | AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read… | |
| Analizada | Crítica (9.8) | 0.47% | — | Esri Portal FOR Arcgis | 7/7/2026 | 9/7/2026 | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with… | |
| Modificada | Crítica (9.8) | 0.85% | — | Esri Portal FOR Arcgis | 7/7/2026 | 29/9/2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other… | |
| Analizada | Alta (8.4) | 0.06% | — | Arcinfo Pcvue | 7/7/2026 | 9/7/2026 | The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to… |