Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.27% | — | Search-guard Search GuardAI | 29/10/2025 | 17/6/2026 | In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP… | |
| Aplazada | Media (6) | 0.27% | — | Search-guard Search Guard FLXAI | 29/10/2025 | 30/9/2026 | In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclusion rule (e.g., ~field) is applied to a field which contains an object as its value, the object is correctly removed from the _source returned by search operations.… | |
| Aplazada | Media (4.3) | 0.13% | — | Premmerce Product Search FOR WoocommerceAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Cross Site Request Forgery.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4. | |
| Aplazada | Media (5.9) | 0.18% | — | Premmerce Product Search FOR WoocommerceAI | 29/10/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through 2.2.7. | |
| Aplazada | Alta (7.1) | 0.14% | — | Andrealandonio Cloud-searchAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search allows Stored XSS.This issue affects CloudSearch: from n/a through <= 3.0.0. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Eyecix JobsearchAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Crocoblock JetsearchAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQL Injection.This issue affects JetSearch: from n/a through <= 3.5.10. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetsearchAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows Reflected XSS.This issue affects JetSearch: from n/a through <= 3.5.10. | |
| Aplazada | Media (4.7) | 0.19% | — | Codeamp Search AND FilterAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17. | |
| Aplazada | Media (6.9) | 0.44% | — | Wikimedia Mediawiki Cirrussearch ExtensionAI | 18/10/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.This issue affects Mediawiki - CirrusSearch Extension: from master before 1.43. | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Advanced Search ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue affects Mediawiki - AdvancedSearch Extension: from master before 1.39. | |
| Aplazada | Alta (8.5) | 0.13% | — | HP Audio PackageAISoundresearch Secomn64AI | 15/10/2025 | 17/6/2026 | Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities | |
| Aplazada | Alta (8.5) | 0.13% | 💥 PoC | HP PC Audio PackageAISoundresearch Secomn64AI | 15/10/2025 | 17/6/2026 | Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities. | |
| Analizada | Alta (7.4) | 0.19% | — | Amazon Opensearch Data Prepper | 15/10/2025 | 30/9/2026 | OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the argument txtusername results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 30/9/2026 | A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the argument txtjobID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.7) | 0.25% | — | Elasticsearch | 10/10/2025 | 17/6/2026 | Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex | |
| Aplazada | Crítica (9.8) | 0.56% | — | Search AND GO - DirectoryAI | 9/10/2025 | 17/6/2026 | The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Ajax WoosearchAI | 2/10/2025 | 17/6/2026 | The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Aplazada | Crítica (9.1) | 0.33% | — | Custom Searchable Data Entry SystemAI | 1/10/2025 | 17/6/2026 | The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated database wiping in versions up to, and including 1.7.1, due to a missing capability check and lack of sufficient validation on the ghazale_sds_delete_entries_table_row() function. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.19% | — | Eulerpool Research SystemsAI | 30/9/2025 | 17/6/2026 | The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' shortcode in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.5) | 0.52% | — | Algoliasearch-helper | 27/9/2025 | 17/6/2026 | Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected… | |
| Aplazada | Media (5.9) | 0.18% | — | Terryl SEO Search PermalinkAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. SEO Search Permalink seo-search-permalink allows Stored XSS.This issue affects SEO Search Permalink: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpo-hr NGG Smart Image SearchAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search: from n/a through <= 3.4.3. |