Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
9650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.55% | — | Lemmy-uiAIMarkdown-it-html5-embedAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a… | |
| Aplazada | Alta (7.2) | 0.54% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid… | |
| Aplazada | Baja (2.3) | 0.40% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go… | |
| Aplazada | Media (5.3) | 0.36% | — | Moby BuildkitAI | 19/8/2026 | 9/9/2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without… | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | Rdk-b WebuiAI | 19/8/2026 | 3/9/2026 | Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter. | |
| Pendiente de análisis | Crítica (9.8) | 0.81% | — | Rdkb WebuiAI | 19/8/2026 | 3/9/2026 | Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request. | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Rdkb-webuiAI | 19/8/2026 | 3/9/2026 | Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. | |
| Pendiente de análisis | Alta (8.1) | 0.36% | — | Rdk-b WebuiAI | 19/8/2026 | 3/9/2026 | Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state. | |
| Pendiente de análisis | Crítica (9.8) | 0.37% | — | Rdk-b WebuiAI | 19/8/2026 | 3/9/2026 | Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature. | |
| Aplazada | Crítica (9.3) | 0.53% | 💥 PoC | Cudy Wr3000AIEclipse MosquittoAI | 19/8/2026 | 9/9/2026 | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to… | |
| Aplazada | Alta (7.5) | 0.60% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Crítica (9.9) | 0.78% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Media (5.4) | 0.25% | — | WPS BidouilleAI | 19/8/2026 | 26/8/2026 | The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users. | |
| Aplazada | Baja (2.7) | 0.30% | — | Expressivequiz Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient… | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided… | |
| Analizada | Media (5.5) | 0.15% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… |