Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 1.0% | — | Silverstripe Advanced WorkflowAISilverstripeAI | 27/8/2026 | 9/9/2026 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When… | |
| Analizada | Media (6.8) | 0.27% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (4.9) | 0.45% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (6.5) | 0.32% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 2/9/2026 | An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Aplazada | Alta (7.5) | 0.53% | — | Advanced Product FieldsAI | 22/8/2026 | 24/8/2026 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch… | |
| Pendiente de análisis | Media (5.4) | 0.35% | — | Redhat Advanced Cluster Management FOR KubernetesAI | 20/8/2026 | 3/9/2026 | A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP… | |
| Aplazada | Alta (7.1) | 0.25% | — | Themehunk Advance Product SearchAI | 20/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | |
| Aplazada | Alta (8.5) | 0.32% | — | Advancedfilemanager Advanced File ManagerAI | 19/8/2026 | 26/8/2026 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle Advanced Inbound Telephony | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound… | |
| Analizada | Alta (8.2) | 0.40% | — | Oracle Advanced Inbound Telephony | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Advanced Inbound… | |
| Pendiente de análisis | Media (4.4) | 0.35% | — | Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 3/9/2026 | A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker… | |
| Pendiente de análisis | Media (5.5) | 0.19% | — | Redhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 5/9/2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially… | |
| Pendiente de análisis | Media (5.5) | 0.11% | — | Redhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 5/9/2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive,… | |
| Pendiente de análisis | Alta (8.8) | 0.81% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI | 18/8/2026 | 27/8/2026 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with… | |
| Aplazada | Media (6.1) | 0.39% | — | Advancedfilemanager Advanced File ManagerAI | 16/8/2026 | 20/8/2026 | The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 12/8/2026 | 5/9/2026 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount… | |
| Pendiente de análisis | Crítica (9.9) | 0.81% | — | Redhat Advanced Cluster ManagementAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel… | |
| Pendiente de análisis | Crítica (9.6) | 0.52% | — | Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure… | |
| Modificada | Alta (7.7) | 0.50% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 11/8/2026 | 5/9/2026 | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every… | |
| Modificada | Media (6.8) | 0.69% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 11/8/2026 | 5/9/2026 | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability… | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 11/8/2026 | 5/9/2026 | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized… | |
| Pendiente de análisis | Crítica (10) | 0.95% | — | Siemens Simatic Iot2050 AdvancedAINodered Node-redAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing… |