Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.22%—Hasura Graphql Engine22/12/202517/6/2026
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
AnalizadaAlta (8.7)0.48%—Hasura Graphql Engine22/12/202517/6/2026
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially…
AnalizadaMedia (6.1)1.1%—Zohocorp Manageengine Applications Manager18/12/202530/9/2026
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
AnalizadaCrítica (9.8)0.20%—Capstone-engine Capstone17/12/202517/6/2026
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit…
AnalizadaAlta (7.8)0.24%—Capstone-engine Capstone17/12/202517/6/2026
Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer overflow in the disassembly path. Commit…
AnalizadaMedia (4.3)0.44%—Zohocorp Manageengine Admanager Plus15/12/20257/10/2026
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
AnalizadaAlta (8.7)3.4%—Yogeshojha Rengine11/12/202517/6/2026
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine…
AplazadaAlta (8.7)0.37%—Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI9/12/202517/6/2026
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.
AplazadaMedia (4.3)0.12%—ShopengineAI3/12/202517/6/2026
The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes…
AplazadaMedia (6.5)0.49%💥 PoCLQD AI Engine FOR WordpressAI25/11/202517/6/2026
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'lqdai_update_post' AJAX endpoint and the use of file_get_contents() with…
AplazadaAlta (8.7)0.24%—3DS Delmia Service Process EngineerAI24/11/202517/6/2026
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
AplazadaCrítica (9.8)0.33%—Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI19/11/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119.
AplazadaMedia (6.8)0.42%—AI EngineAI18/11/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from…
AplazadaAlta (7.1)0.42%—AI EngineAI13/11/20257/10/2026
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.5)0.14%—Altair Grid EngineAI11/11/202517/6/2026
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with…
AplazadaMedia (6.8)0.13%—Altair Grid EngineAI11/11/202517/6/2026
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password hash information when processing user authentication requests. This could allow a local attacker to extract password hashes for privileged…
AplazadaMedia (6.5)0.42%—Zoho Manageengine OpmanagerAI11/11/202517/6/2026
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
AplazadaCrítica (9.8)1.7%—Zohocorp Manageengine Analytics PlusAI11/11/202517/6/2026
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
AplazadaAlta (8.8)4.2%💥 PoCZohocorp Manageengine Applications ManagerAI11/11/202525/9/2026
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
AnalizadaMedia (6.1)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
AnalizadaMedia (5.5)0.44%—Fabian Online JOB Search Engine10/11/20257/10/2026
A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AplazadaMedia (5.3)0.31%—Amazon Research AND Engineering StudioAI6/11/20257/10/2026
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users…