Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
9651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.17% | — | Pv-bhat Gemsuite-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument file_path/file_paths results in path traversal. The… | |
| Aplazada | Baja (1.9) | 1.1% | — | Adolfosalasgomez3011 Slidev-builder-mcpAI | 8/8/2026 | 12/8/2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with… | |
| Aplazada | Baja (1.9) | 0.17% | — | Hulupeep Mcp-ui-probeAI | 8/8/2026 | 14/8/2026 | A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack… | |
| Aplazada | Media (6.9) | 2.1% | — | Inquirelab Mcp-bridge-apiAI | 8/8/2026 | 12/8/2026 | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection. It is possible to initiate… | |
| Pendiente de análisis | Media (4) | 0.27% | — | Adobe Genuine Software Integrity ServiceAI | 7/8/2026 | 17/8/2026 | Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require… | |
| Aplazada | Alta (8.7) | 0.50% | — | Joomshaper SP Page BuilderAI | 7/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their… | |
| Aplazada | Alta (7.5) | 0.36% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept… | |
| Aplazada | Media (6.5) | 0.34% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. | |
| Aplazada | Alta (8.1) | 0.38% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | |
| Aplazada | Media (4.3) | 0.28% | — | Swagger UIAIWso2 API PublisherAI | 6/8/2026 | 29/9/2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API… | |
| Aplazada | Media (5.9) | 0.24% | — | Markjaquith Subscribe TO CommentsAI | 6/8/2026 | 12/8/2026 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Cozmoslabs Profile BuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Squirrly SEOAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WpbruiserAI | 6/8/2026 | 12/8/2026 | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins AWS Codebuild PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | |
| Analizada | Crítica (9.8) | 0.31% | — | Redhat Build OF Keycloak | 5/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked… | |
| Analizada | Media (4.3) | 0.19% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the… | |
| Analizada | Alta (8.8) | 0.65% | — | Redhat Build OF Keycloak | 5/8/2026 | 10/8/2026 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Media (6.5) | 0.55% | — | Redhat Build OF Keycloak | 5/8/2026 | 31/8/2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a… | |
| Modificada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 5/8/2026 | 31/8/2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located… |