Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.13% | — | Arcinfo Pcvue | 7/7/2026 | 9/7/2026 | Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability. | |
| Modificada | Crítica (9.8) | 0.62% | — | Esri Arcgis Server | 6/7/2026 | 8/7/2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS… | |
| Modificada | Alta (7.5) | 1.2% | — | Esri Arcgis Server | 6/7/2026 | 8/7/2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full… | |
| Aplazada | Baja (2.1) | 0.48% | — | Nousresearch Hermes-agentAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.2) | 1.4% | 💥 Exploit | Circl Cve-searchAI | 5/7/2026 | 6/7/2026 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose… | |
| Aplazada | Media (5.5) | 0.77% | 💥 PoC | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.9) | 0.55% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 7/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (1.3) | 0.37% | — | Nousresearch Hermes-agentAI | 3/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to improper handling of case sensitivity. The… | |
| Aplazada | Alta (7) | 0.28% | — | Tp-link Archer C5AI | 2/7/2026 | 2/7/2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with administrative privileges can inject crafted… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Fast Total SearchAI | 2/7/2026 | 2/7/2026 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Search Atlas SEOAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions. | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests. | |
| Analizada | Media (4.9) | 0.50% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 1/7/2026 | 2/7/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable. | |
| Aplazada | Media (5.9) | 0.46% | — | Tp-link Archer Ax20 V2AI | 30/6/2026 | 2/7/2026 | An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may… | |
| Pendiente de análisis | Alta (7.5) | 0.73% | — | LibarchiveAI | 30/6/2026 | 2/10/2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory… | |
| Aplazada | Baja (1.3) | 0.13% | — | Arc53 DocsgptAI | 28/6/2026 | 29/6/2026 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (4.4) | 0.40% | — | Ivorysearch Ivory SearchAI | 27/6/2026 | 29/6/2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Themehunk Advance Product SearchAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | SearchplusAI | 24/6/2026 | 25/6/2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both… | |
| Analizada | Alta (8.8) | 0.48% | — | Joomlaboat Extra Search | 19/6/2026 | 19/8/2026 | Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | JobsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | JetsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |