Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 29/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <=… | |
| Aplazada | Media (5.5) | 0.51% | — | Alejandroarciniegas Mcp-data-visAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request… | |
| Aplazada | Baja (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be launched remotely. A… | |
| Aplazada | Baja (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. The complexity of… | |
| Aplazada | Media (6.1) | 0.19% | — | MaharaAIElasticsearch7AI | 24/4/2026 | 17/6/2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter. | |
| Analizada | Alta (7.5) | 0.44% | — | Oracle HCM Common Architecture | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.… | |
| Analizada | Crítica (9.8) | 0.48% | — | Esri Portal FOR Arcgis | 21/4/2026 | 17/6/2026 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. | |
| Analizada | Alta (7.2) | 0.47% | — | Esri Portal FOR Arcgis | 21/4/2026 | 17/6/2026 | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. | |
| Pendiente de análisis | Media (6.2) | 0.15% | — | Sparxsystems Enterprise ArchitectAI | 17/4/2026 | 7/10/2026 | Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the plaintext secret to exchange it into an access and id tokens as part of the OpenID authentication flow. | |
| Analizada | Media (5.7) | 0.11% | — | Sparxsystems Enterprise Architect | 16/4/2026 | 7/10/2026 | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication | |
| Pendiente de análisis | Media (5.1) | 0.24% | — | Arcserve UDP ConsoleAI | 16/4/2026 | 17/6/2026 | UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure. | |
| Analizada | Media (5.4) | 0.11% | — | Tp-link Archer C7 Firmware | 16/4/2026 | 17/6/2026 | Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login. An adjacent attacker with the ability to intercept network traffic… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Barcode ScannerAI | 16/4/2026 | 17/6/2026 | The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php. | |
| Analizada | Media (6.5) | 0.72% | 💥 Exploit | Getarcane Arcane | 10/4/2026 | 17/6/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server's… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | 💥 PoC | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Modificada | Alta (8.5) | 1.8% | — | Tp-link Archer Ax53 Firmware | 8/4/2026 | 25/7/2026 | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to modify device… | |
| Modificada | Media (6.8) | 0.36% | — | Tp-link Archer Ax53 Firmware | 8/4/2026 | 25/7/2026 | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing… | |
| Modificada | Media (6.8) | 0.36% | — | Tp-link Archer Ax53 Firmware | 8/4/2026 | 25/7/2026 | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing… | |
| Modificada | Alta (8.5) | 2.2% | — | Tp-link Archer Ax53 Firmware | 8/4/2026 | 25/7/2026 | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration… | |
| Modificada | Alta (7.3) | 0.56% | — | Tp-link Archer Ax53 Firmware | 8/4/2026 | 25/7/2026 | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code… | |
| Aplazada | Media (5.5) | 2.1% | — | Suvarchal Docker-mcp-serverAI | 7/4/2026 | 24/7/2026 | A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The… | |
| Modificada | Media (5.5) | 0.17% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/4/2026 | 1/9/2026 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate… |