Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

8451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.34%—Gvectors WpdiscuzAI30/12/20257/10/2026
Vulnerabilidad de omisión de autorización a través de una clave controlada por el usuario en AdvancedCoding wpDiscuz wpdiscuz permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a wpDiscuz: desde n/a hasta menor o igual a 7.6.40.
AplazadaMedia (5.9)0.21%—Amp-mode Review-disclaimerAI24/12/20257/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en AMP-MODE Review Disclaimer review-disclaimer permite XSS Almacenado. Este problema afecta a Review Disclaimer: desde n/a hasta menor o igual que 2.0.3.
AplazadaMedia (4.3)0.23%—Mojofywp WP Affiliate DisclosureAI21/12/202517/6/2026
Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.
AnalizadaCrítica (10)32%⚠ Explotación activa💥 PoCCisco Asyncos17/12/202517/6/2026
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient…
AplazadaAlta (8.3)0.26%—Soliscloud APIAI4/12/202517/6/2026
The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.
AplazadaMedia (5.3)0.30%—Softdiscover ZigaformAI2/12/202517/6/2026
The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or access rights. This makes it possible…
AplazadaMedia (4.2)0.10%—Wisc HtcondorAI30/11/202517/6/2026
HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3.
AnalizadaAlta (8.8)0.73%—Aiscatcher Ais-catcher29/11/20257/10/2026
AIS-catcher es un receptor AIS multiplataforma. Antes de la versión 0.64, existe una vulnerabilidad de desbordamiento negativo de enteros en la lógica de análisis MQTT de AIS-catcher. Esta vulnerabilidad permite a un atacante activar un desbordamiento de búfer de montón masivo enviando un paquete MQTT malformado con…
AnalizadaCrítica (9.3)0.51%—Aiscatcher Ais-catcher29/11/20257/10/2026
AIS-catcher es un receptor AIS multiplataforma. Antes de la versión 0.64, una vulnerabilidad de desbordamiento de búfer de pila ha sido identificada en la clase AIS::Message de AIS-catcher. Esta vulnerabilidad permite a un atacante escribir aproximadamente 1KB de datos arbitrarios en un búfer de 128 bytes. Este…
ModificadaAlta (7.7)0.32%—Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+2526/11/202531/8/2026
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,…
AplazadaAlta (7.4)0.20%—Cisco Asr1903AICisco Asr3901AI26/11/202517/6/2026
Vulnerabilidad de lectura fuera de límites en ASR1903 y ASR3901 en ASR Lapwing_Linux en Linux (módulos nr_fw). Esta vulnerabilidad está asociada con los archivos de programa Code/nr_fw/DLP/src/NrCgi.C. Este problema afecta a Lapwing_Linux: antes del 26/11/2025.
AplazadaAlta (8.8)0.51%—Cisco Catalyst Center Virtual ApplianceAI13/11/202517/6/2026
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP…
AplazadaMedia (4.7)0.25%—Cisco Catalyst Center Virtual ApplianceAI13/11/20257/10/2026
Una vulnerabilidad en la interfaz de gestión basada en web de Cisco Catalyst Center Virtual Appliance podría permitir a un atacante remoto no autenticado redirigir a un usuario a una página web maliciosa. Esta vulnerabilidad se debe a una validación de entrada incorrecta de los parámetros de solicitud HTTP. Un…
AnalizadaMedia (6.1)0.22%—Cisco Catalyst Center13/11/20257/10/2026
Una vulnerabilidad en la interfaz de gestión basada en web de Cisco Catalyst Center podría permitir a un atacante remoto no autenticado realizar un ataque de cross-site scripting (XSS) contra un usuario de la interfaz de un dispositivo afectado. Esta vulnerabilidad se debe a una validación insuficiente de la entrada…
AnalizadaAlta (8.8)0.36%—Cisco Catalyst Center13/11/20257/10/2026
Una vulnerabilidad en la API REST de Cisco Catalyst Center podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en un contenedor restringido como el usuario root. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario en los parámetros de…
AnalizadaMedia (4.3)0.27%—Cisco Catalyst Center13/11/20257/10/2026
Una vulnerabilidad en Cisco Catalyst Center podría permitir a un atacante remoto autenticado ejecutar operaciones que deberían requerir privilegios de Administrador. El atacante necesitaría credenciales de usuario válidas de solo lectura. Esta vulnerabilidad se debe a un control de acceso basado en roles (RBAC)…
AplazadaCrítica (9.1)0.47%—Acowebs Dynamic Pricing With Discount Rules FOR WoocommerceAI6/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing allows Code Injection.This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through <= 4.5.9.
AplazadaMedia (4.3)0.27%—Cisco Unified Intelligence CenterAI5/11/202517/6/2026
A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (7.2)0.48%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exploit this vulnerability by uploading a malicious file to the…
AnalizadaAlta (7.2)0.39%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by uploading a crafted file to the web…
AnalizadaMedia (4.9)1.1%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a…
AnalizadaCrítica (9.8)0.92%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the…
AnalizadaCrítica (9.8)0.87%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are…
AnalizadaAlta (7.5)0.71%💥 PoCCisco Identity Services Engine5/11/202517/6/2026
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a…
AnalizadaMedia (4.9)0.30%—Cisco Identity Services Engine5/11/202517/6/2026
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could…