Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Modificada | Media (5.5) | 0.27% | — | IBM APP Connect EnterpriseIBM Integration BUS | 30/6/2026 | 20/7/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. | |
| Aplazada | Alta (7.3) | 0.12% | — | O+ ConnectAI | 29/6/2026 | 29/6/2026 | Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. | |
| Pendiente de análisis | Media (4.8) | 0.38% | — | Rapid7 Insightconnect Markdown PluginAI | 26/6/2026 | 24/7/2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial… | |
| Analizada | Media (4.3) | 0.29% | — | Rapid7 Insightconnect Compression | 25/6/2026 | 29/6/2026 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker. | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect Tcpdump | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect Traceroute | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands. | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect Translate | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction. | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect Finger | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction. | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect Ping | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect AWK | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline. | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect RPM | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization in shell command construction. | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect Sqlmap | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation. | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpforms WP Forms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Wpforms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that… | |
| Pendiente de análisis | Baja (3.5) | 0.16% | — | HCL ConnectionsAI | 23/6/2026 | 6/10/2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario. | |
| Aplazada | Media (5.3) | 0.46% | — | 2download Connector FOR 2DL Hosted CheckoutAI | 19/6/2026 | 22/6/2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary… | |
| Aplazada | Media (5.9) | 0.47% | — | Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect… | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Identity Manager… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Database User). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager… | |
| Aplazada | Alta (7.5) | 0.39% | — | E4jconnect VikrentcarAI | 15/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. |