Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.39% | — | Tempo OperatorAIJaeger UIAI | 2/4/2025 | 8/9/2026 | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user… | |
| Aplazada | Media (4.3) | 0.37% | — | Tempo OperatorAI | 2/4/2025 | 8/9/2026 | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and… | |
| Aplazada | Media (6.4) | 0.31% | — | Contempo Real Estate CoreAI | 1/4/2025 | 17/6/2026 | The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Aplazada | Alta (8.8) | 0.74% | — | Contempothemes Real Estate 7AI | 1/4/2025 | 17/6/2026 | The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary… | |
| Aplazada | Media (5.3) | 0.33% | — | Amazon IAM Identity CenterAIAmazon Temporary Elevated Access ManagementAI | 4/3/2025 | 17/6/2026 | Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process | |
| Analizada | Crítica (9.8) | 0.78% | — | Contempothemes Real Estate 7 | 12/2/2025 | 17/6/2026 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new… | |
| Aplazada | Baja (2) | 0.09% | — | Temporal Api-goAI | 12/2/2025 | 17/6/2026 | The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response` field not having Data Converter… | |
| Aplazada | Media (6.5) | 0.37% | — | Mliebelt Chess Tempo ViewerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mliebelt Chess Tempo Viewer chesstempoviewer allows Stored XSS.This issue affects Chess Tempo Viewer: from n/a through <= 0.9.5. | |
| Analizada | Media (6.1) | 0.32% | — | Contempo PDF Image Generator | 1/10/2024 | 17/6/2026 | The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Aplazada | Alta (8.7) | 1.3% | — | Contemporary Control Systems Basrouter BacnetAI | 14/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (6.5) | 0.44% | — | Contemporary Controls Basrouter Bacnet Basrt-bAI | 27/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of… | |
| Aplazada | Media (4.4) | 0.49% | — | Temporal ServerAI | 3/4/2024 | 17/6/2026 | Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task containing the invalid UTF-8 will become… | |
| Aplazada | Media (4.3) | 0.39% | — | Uber CadenceAITemporalAI | 2/4/2024 | 17/6/2026 | For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when a victim views that signal. The XSS is in the timeline page displaying the workflow execution details of the workflow that was sent the crafted signal. Access to send a signal to a… | |
| Modificada | Crítica (9.8) | 0.68% | — | Vanderschaarlab Temporai | 26/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.8) | 0.67% | — | Vanderschaarlab Temporai | 26/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Baja (3.6) | 0.17% | — | Temporal | 30/6/2023 | 17/6/2026 | Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done outside of the normal Temporal server flow. It requires the namespace UUID and… | |
| Modificada | Media (6.1) | 0.38% | — | Contempothemes Real Estate 7 | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. | |
| Modificada | Media (4.3) | 0.36% | — | Storeapps Temporary Login Without Password | 13/12/2021 | 17/6/2026 | The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Contempothemes Real Estate 7 | 6/7/2021 | 17/6/2026 | The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context | |
| Modificada | Alta (7.8) | 0.70% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db. | |
| Modificada | Alta (7.8) | 0.56% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx. | |
| Modificada | Media (6.6) | 0.51% | — | HP SGI Tempo | 27/1/2020 | 17/6/2026 | SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw. | |
| Modificada | Media (4.3) | 1.1% | — | Tempo | 31/10/2019 | 17/6/2026 | An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can obtain the summary for issues they do not have permission to view via the Tempo plugin. | |
| Modificada | Media (6.1) | 0.90% | — | Opentext Tempo BOX | 10/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image. |