Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)1.1%💥 PoCAI EngineAI31/7/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected…
AnalizadaMedia (5.5)0.52%—Phpgurukul Local Services Search Engine Management System26/7/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The…
AplazadaMedia (6.5)0.54%—AI EngineAI24/7/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AnalizadaAlta (8.8)0.40%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
AnalizadaAlta (8.8)0.42%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
AnalizadaAlta (7.5)0.10%—IBM Engineering Systems Design Rhapsody23/7/202517/6/2026
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.
AnalizadaMedia (5.4)0.40%—Zohocorp Manageengine Applications Manager23/7/202517/6/2026
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
AnalizadaCrítica (10)68%⚠ Explotación activaCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation…
AnalizadaMedia (4.1)0.42%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured…
AnalizadaAlta (7.2)19%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this…
AnalizadaAlta (7.2)9.9%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this…
AplazadaCrítica (9.3)3.6%💥 ExploitBuilderengineAIElfinderAIJquery File UploadAI10/7/202517/6/2026
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php…
AnalizadaMedia (5.4)0.18%—Meowapps AI Engine8/7/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaMedia (5.9)0.33%—IBM Engineering Requirements Management DoorsIBM Engineering Requirements Management Doors WEB Access7/7/202517/6/2026
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
AnalizadaAlta (8)0.37%—Meowapps AI Engine4/7/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain…
AnalizadaMedia (5.5)0.49%—Phpgurukul Local Services Search Engine Management System29/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely.…
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
AnalizadaCrítica (10)39%💥 ExploitCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector25/6/202517/6/2026
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent…
AnalizadaCrítica (10)98%⚠ Explotación activa💥 ExploitCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector25/6/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation…
AnalizadaMedia (6.4)0.36%—Cisco Identity Services Engine25/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.
AplazadaMedia (6.5)0.23%—Jordymeow Code EngineAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Code Engine code-engine allows Stored XSS.This issue affects Code Engine: from n/a through <= 0.3.2.
AplazadaMedia (6.5)0.23%—Wpengine Gutenberg Blocks ACF Blocks SuiteAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Engine Gutenberg Blocks – ACF Blocks Suite acf-blocks allows Stored XSS.This issue affects Gutenberg Blocks – ACF Blocks Suite: from n/a through <= 2.6.11.
AplazadaMedia (4.3)0.15%—Oganro Pixelbeds Channel Manager AND Hotel Booking EngineAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-channel-manager-booking-engine allows Cross Site Request Forgery.This issue affects PixelBeds Channel Manager and Hotel Booking Engine: from n/a through <= 1.0.
AnalizadaAlta (8.8)0.67%—Meowapps AI Engine19/6/202517/6/2026
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to have…