Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

11.348 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.15%—Openstack Ironic Python AgentAI24/7/20269/9/2026
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
AnalizadaCrítica (9.9)0.79%—Microsoft Azure RED HAT Openshift24/7/20267/8/2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
AplazadaCrítica (9.6)0.20%—Ninjaforms File Uploads ExtensionAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
Pendiente de análisisAlta (8.8)0.46%—Redhat Openshift AIAIRedhat ODH DashboardAI23/7/202630/9/2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the…
AplazadaMedia (5.4)0.23%—Regularlabs Joomla ExtensionsAIJoomlaAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.
AplazadaAlta (7.5)0.42%—Regularlabs Regular Labs ExtensionsAIJoomlaAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored…
AplazadaAlta (8.8)0.20%—JoomlaAIRegularlabs Extension ManagerAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could…
AplazadaAlta (8.8)0.20%—Regularlabs ExtensionsAIJoomlaAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend…
AplazadaAlta (8.8)0.14%—Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI22/7/202622/7/2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory…
AplazadaMedia (6.5)0.47%—Contact Form 7 Dynamic Text ExtensionAI22/7/202629/9/2026
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible…
AnalizadaCrítica (9.4)0.46%—Oracle Peoplesoft Enterprise FIN Expenses21/7/20266/8/2026
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks…
AplazadaCrítica (10)0.45%—Dj-extensions Dj-jdownloadsAI20/7/202623/7/2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
AplazadaCrítica (10)0.45%💥 PoCDj-extensions Dj-classifiedsAI20/7/202623/7/2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
AnalizadaMedia (4.4)0.19%—Msiemens Rust Onenote File Parser20/7/202618/8/2026
Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed…
AplazadaMedia (5.3)0.30%—Wensolutions WP TravelAI20/7/202620/7/2026
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
AnalizadaMedia (5.1)0.13%—Sfackler Openssl17/7/202629/7/2026
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL…
AplazadaMedia (5.3)0.39%—Fense Proxy VPN BlockerAI17/7/202621/7/2026
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*…
AnalizadaMedia (4.3)0.40%—Facelessuser Pymdown Extensions16/7/202630/7/2026
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files…
AplazadaCrítica (9.8)1.6%💥 ExploitKopiaAIOpenbsd OpensshAI16/7/202616/7/2026
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards…
Pendiente de análisisAlta (7.5)0.82%—Opensuse LibsolvAI16/7/202631/8/2026
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted…
AplazadaAlta (7.7)0.39%—Redhat Openshift GitopsAIArgoproj Argo CDAI15/7/202616/7/2026
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a…
AplazadaMedia (6.2)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.4)0.16%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
AplazadaAlta (7.8)0.35%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
AplazadaAlta (7.5)0.31%—Nvidia Tensorrt-llmAI14/7/202615/7/2026
NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.