Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1095 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/20261/10/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Pendiente de análisisMedia (5.5)0.27%💥 PoCWikimedia CirrussearchAI24/9/202624/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.
Pendiente de análisisAlta (7.4)0.20%—Thebrowser ARC SearchAI23/9/202624/9/2026
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about…
AplazadaAlta (8.4)0.27%—Klever-goAIElasticsearchAI23/9/202624/9/2026
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account…
AplazadaCrítica (9.3)0.39%💥 PoCOrdasoft Osgallery SearchAIJoomlaAI20/9/202622/9/2026
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a…
AplazadaMedia (4.3)0.23%—Search Atlas SEOAI19/9/202621/9/2026
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaMedia (6.5)0.22%—JetsearchAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
AplazadaAlta (8.7)0.52%—Manticore SearchAI16/9/202622/9/2026
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that…
AplazadaAlta (7.1)0.48%—Zlt2000 Microservices-platformAIElasticsearchAI16/9/202618/9/2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (7.5)0.32%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (7.8)0.16%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle…
AplazadaAlta (7.8)0.12%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search…
AplazadaAlta (7.8)0.16%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (7.5)0.31%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (7)0.12%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where…
AplazadaAlta (7.7)0.34%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
Orbitaley — Vulnerabilidades