Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
11.348 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.15% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 9/9/2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |
| Analizada | Crítica (9.9) | 0.79% | — | Microsoft Azure RED HAT Openshift | 24/7/2026 | 7/8/2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Aplazada | Media (5.4) | 0.23% | — | Regularlabs Joomla ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers. | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Regular Labs ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored… | |
| Aplazada | Alta (8.8) | 0.20% | — | JoomlaAIRegularlabs Extension ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could… | |
| Aplazada | Alta (8.8) | 0.20% | — | Regularlabs ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend… | |
| Aplazada | Alta (8.8) | 0.14% | — | Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI | 22/7/2026 | 22/7/2026 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory… | |
| Aplazada | Media (6.5) | 0.47% | — | Contact Form 7 Dynamic Text ExtensionAI | 22/7/2026 | 29/9/2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible… | |
| Analizada | Crítica (9.4) | 0.46% | — | Oracle Peoplesoft Enterprise FIN Expenses | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks… | |
| Aplazada | Crítica (10) | 0.45% | — | Dj-extensions Dj-jdownloadsAI | 20/7/2026 | 23/7/2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| Aplazada | Crítica (10) | 0.45% | 💥 PoC | Dj-extensions Dj-classifiedsAI | 20/7/2026 | 23/7/2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| Analizada | Media (4.4) | 0.19% | — | Msiemens Rust Onenote File Parser | 20/7/2026 | 18/8/2026 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed… | |
| Aplazada | Media (5.3) | 0.30% | — | Wensolutions WP TravelAI | 20/7/2026 | 20/7/2026 | The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site. | |
| Analizada | Media (5.1) | 0.13% | — | Sfackler Openssl | 17/7/2026 | 29/7/2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL… | |
| Aplazada | Media (5.3) | 0.39% | — | Fense Proxy VPN BlockerAI | 17/7/2026 | 21/7/2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*… | |
| Analizada | Media (4.3) | 0.40% | — | Facelessuser Pymdown Extensions | 16/7/2026 | 30/7/2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files… | |
| Aplazada | Crítica (9.8) | 1.6% | 💥 Exploit | KopiaAIOpenbsd OpensshAI | 16/7/2026 | 16/7/2026 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards… | |
| Pendiente de análisis | Alta (7.5) | 0.82% | — | Opensuse LibsolvAI | 16/7/2026 | 31/8/2026 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted… | |
| Aplazada | Alta (7.7) | 0.39% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 15/7/2026 | 16/7/2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a… | |
| Aplazada | Media (6.2) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.4) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Aplazada | Alta (7.8) | 0.35% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service. | |
| Aplazada | Alta (7.5) | 0.31% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service. |