Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6561 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.59% | — | Jinher OA C6AI | 29/7/2026 | 30/7/2026 | Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack. | |
| Analizada | Alta (7.3) | 0.19% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site. | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins. | |
| Analizada | Crítica (9.2) | 0.55% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. | |
| Analizada | Media (6.1) | 0.27% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | |
| Analizada | Media (5.3) | 0.35% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | |
| Analizada | Media (5.3) | 0.34% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | |
| Analizada | Crítica (9.2) | 0.50% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | |
| Analizada | Crítica (9.2) | 0.44% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories. | |
| Analizada | Crítica (9.4) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker. | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions. | |
| Analizada | Media (6.5) | 0.31% | — | Redhat Build OF Keycloak | 29/7/2026 | 11/8/2026 | A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group… | |
| Modificada | Media (5.5) | 0.38% | — | Redhat Build OF Keycloak | 29/7/2026 | 16/9/2026 | Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could… | |
| Aplazada | Alta (7.2) | 1.2% | — | Easydigitaldownloads Easy Digital DownloadsAI | 29/7/2026 | 30/7/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header… | |
| Pendiente de análisis | Alta (7.2) | 0.19% | — | Atlassian OauthAI | 28/7/2026 | 9/9/2026 | OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and… | |
| Pendiente de análisis | Alta (8.6) | 0.45% | — | Oauth2AI | 28/7/2026 | 5/10/2026 | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host,… | |
| Pendiente de análisis | Alta (8.5) | 0.53% | — | Openshift Oauth-proxyAI | 28/7/2026 | 21/9/2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated… | |
| Aplazada | Crítica (10) | 0.77% | — | Balbooa FormsAI | 28/7/2026 | 28/7/2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. | |
| Aplazada | Media (4.9) | 0.50% | — | Easydigitaldownloads Easy Digital DownloadsAI | 27/7/2026 | 27/7/2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+1 | 27/7/2026 | 11/8/2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… |