Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.50%—SignozAI17/9/202622/9/2026
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary…
Pendiente de análisisAlta (8.4)0.40%—SignozAI17/9/202622/9/2026
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries…
AplazadaCrítica (9.8)0.61%—Headless Single Sign ONAI17/9/202617/9/2026
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
AplazadaAlta (8.7)0.59%—OpensignAI16/9/202622/9/2026
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download…
AplazadaAlta (8.8)0.58%—SignozAI16/9/202621/9/2026
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without…
Pendiente de análisisAlta (8.8)0.42%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.43%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
Pendiente de análisisAlta (8.1)0.35%—Oracle Demand Signal RepositoryAIOracle E-business SuiteAI15/9/202618/9/2026
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.…
AplazadaMedia (5.1)0.36%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
AplazadaMedia (5.1)0.51%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a malicious archive parameter.
AplazadaAlta (8.7)0.46%—Design Scuole ItaliaAI15/9/202618/9/2026
The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An unauthenticated RSS feed at /circolare/feed/…
AplazadaAlta (8.7)0.54%—Wordpress Design Scuole ItaliaAI15/9/202618/9/2026
A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.
AplazadaMedia (5.8)0.30%—Signalk Signal K ServerAI15/9/202630/9/2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the…
Pendiente de análisisBaja (2.3)0.16%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can reveal information to the client side. Three specific properties were identified: The…
Pendiente de análisisMedia (4.9)0.39%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the…
Pendiente de análisisBaja (2.7)0.29%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server…
AplazadaAlta (7.5)0.50%—Signalwire LibksAI11/9/202630/9/2026
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."…
AplazadaAlta (7.5)0.35%—Shirt Product DesignerAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Pendiente de análisisAlta (7.1)0.10%—Redpine Signals Rs9116wAIRedpine Signals Siwx917AI8/9/20268/9/2026
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
AplazadaAlta (7.2)0.42%—Codesigner User Profile BuilderAI7/9/20269/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (6.9)0.10%—UpsignonAI2/9/20268/9/2026
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive…
AplazadaMedia (6.9)0.16%—UpsignonAI2/9/20268/9/2026
UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt. Attackers can access the stored biometric key from a standard local process…
AplazadaMedia (6.9)0.10%—UpsignonAI2/9/20268/9/2026
UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup…