Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

6561 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.59%—Jinher OA C6AI29/7/202630/7/2026
Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.
AnalizadaAlta (7.3)0.19%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
AnalizadaCrítica (9.2)0.55%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
AnalizadaMedia (6.1)0.27%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
AnalizadaMedia (5.3)0.35%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
AnalizadaMedia (5.3)0.34%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
AnalizadaCrítica (9.2)0.50%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
AnalizadaCrítica (9.2)0.44%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
AnalizadaCrítica (9.4)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
AnalizadaMedia (6.5)0.31%—Redhat Build OF Keycloak29/7/202611/8/2026
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group…
ModificadaMedia (5.5)0.38%—Redhat Build OF Keycloak29/7/202616/9/2026
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could…
AplazadaAlta (7.2)1.2%—Easydigitaldownloads Easy Digital DownloadsAI29/7/202630/7/2026
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header…
Pendiente de análisisAlta (7.2)0.19%—Atlassian OauthAI28/7/20269/9/2026
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and…
Pendiente de análisisAlta (8.6)0.45%—Oauth2AI28/7/20265/10/2026
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host,…
Pendiente de análisisAlta (8.5)0.53%—Openshift Oauth-proxyAI28/7/202621/9/2026
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated…
AplazadaCrítica (10)0.77%—Balbooa FormsAI28/7/202628/7/2026
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
AplazadaMedia (4.9)0.50%—Easydigitaldownloads Easy Digital DownloadsAI27/7/202627/7/2026
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
AnalizadaAlta (8)0.26%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+127/7/202611/8/2026
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their…
AnalizadaAlta (8)0.26%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially…
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,…
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially…