Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6558 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.12% | — | Intel Workload Sevices Framework | 11/8/2026 | 2/10/2026 | Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur… | |
| Aplazada | Alta (8.8) | 0.40% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts… | |
| Aplazada | Alta (8.8) | 0.42% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group… | |
| Pendiente de análisis | Alta (8.8) | 0.60% | — | Opendatahub ODH DashboardAI | 10/8/2026 | 14/8/2026 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Redhat ODH DashboardAI | 10/8/2026 | 28/9/2026 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to… | |
| Aplazada | Alta (8.6) | 0.50% | — | Duhow Xiaoai-patchAI | 10/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal or external URLs. The /auth endpoint in api/main.py uses the user-supplied url POST parameter to redirect to a Home… | |
| Aplazada | Crítica (9.8) | 1.7% | — | Duhow Xiaoai-patchAI | 10/8/2026 | 28/8/2026 | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute and /unmute endpoint handlers in api/main.py pass the user-supplied silent query parameter directly to os.system()… | |
| Aplazada | Alta (8.6) | 0.45% | — | Iptanus File UploadAI | 9/8/2026 | 26/8/2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | |
| Aplazada | Media (5.3) | 0.30% | — | Download MonitorAI | 8/8/2026 | 26/8/2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics. | |
| Aplazada | Crítica (9.8) | 0.73% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | |
| Aplazada | Crítica (9.8) | 10% | 💥 Exploit | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wordpress File UploadAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Oauth ServerAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | BOX NOW Delivery CroatiaAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Media (5.3) | 0.16% | — | Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated… | |
| Aplazada | Alta (8.1) | 0.87% | — | Wpmudev Wpmu DEV DashboardAI | 6/8/2026 | 12/8/2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by… | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Openshift Oauth-proxyAI | 5/8/2026 | 6/8/2026 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject… | |
| Analizada | Crítica (9.8) | 0.31% | — | Redhat Build OF Keycloak | 5/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked… | |
| Pendiente de análisis | Crítica (9.4) | 0.23% | — | Google Chronicle SoarAI | 5/8/2026 | 31/8/2026 | Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no… | |
| Analizada | Alta (8.8) | 0.65% | — | Redhat Build OF Keycloak | 5/8/2026 | 10/8/2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… |