Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
6562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… | |
| Aplazada | Alta (7.5) | 0.39% | — | Download ManagerAI | 27/7/2026 | 27/7/2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected… | |
| Aplazada | Media (6.4) | 0.35% | — | Yoast SEOAI | 25/7/2026 | 27/7/2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Build OF Keycloak | 24/7/2026 | 16/9/2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a… | |
| Modificada | Media (4.9) | 0.42% | — | Redhat Build OF Keycloak | 24/7/2026 | 19/8/2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve… | |
| Aplazada | Media (4.3) | 0.25% | — | CYR TO LAT ReloadedAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Media (5.3) | 0.38% | — | Broadcast Live VideoAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | CoachingAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Regularlabs Keyboard ShortcutsAI | 23/7/2026 | 23/7/2026 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Aplazada | Media (5.5) | 0.69% | — | Boazsegev Facil.ioAI | 23/7/2026 | 23/7/2026 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to… | |
| Aplazada | Media (5.5) | 0.52% | — | Boazsegev Facil.ioAI | 23/7/2026 | 23/7/2026 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack can be initiated… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Loans | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this… | |
| Analizada | Alta (7.7) | 0.39% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Alta (8.2) | 0.44% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle SOA Suite | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Enterprise Scheduling System). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.… | |
| Aplazada | Media (5.5) | 0.15% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 24/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… |