Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

9651 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.39%—Redhat Build OF Keycloak2/8/202616/9/2026
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time.…
ModificadaAlta (7.2)0.55%—Redhat Build OF Keycloak2/8/202616/9/2026
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized…
ModificadaMedia (5.4)0.30%—Redhat Build OF Keycloak2/8/202616/9/2026
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed…
AplazadaAlta (8.1)0.38%—Codesmiths User Profile BuilderAI1/8/202626/8/2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported…
AplazadaMedia (5.4)0.23%—Codeless Page BuilderAI1/8/202626/8/2026
The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before using it as an HTML tag name when rendering content, allowing users with contributor-level access and above to inject arbitrary HTML and JavaScript that executes in the session of any higher-privileged…
AplazadaBaja (3.7)0.30%—BuilderallAI1/8/202626/8/2026
The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing unauthenticated attackers to complete the connection flow and overwrite the stored third-party integration access token. A durable overwrite requires the…
AplazadaCrítica (9.3)1.1%💥 PoCComfyuiAI31/7/20269/9/2026
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated…
ModificadaMedia (5.4)0.29%—Redhat Build OF Keycloak31/7/202616/9/2026
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation…
AnalizadaMedia (4.7)0.33%—Redhat Build OF Keycloak31/7/20267/8/2026
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that…
ModificadaAlta (8.1)0.40%—Redhat Build OF Keycloak31/7/202616/9/2026
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization…
ModificadaAlta (8.1)0.40%—Redhat Build OF Keycloak31/7/202616/9/2026
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a…
AnalizadaMedia (5.4)0.31%—Redhat Build OF Keycloak31/7/20267/8/2026
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address…
ModificadaMedia (4.7)0.41%—Redhat Build OF Keycloak31/7/202616/9/2026
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is…
AnalizadaMedia (6.5)0.34%—Redhat Build OF Keycloak31/7/20267/8/2026
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses,…
AnalizadaBaja (3.7)0.32%—Redhat Build OF Keycloak31/7/20267/8/2026
A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any…
AnalizadaMedia (6.5)0.31%—Redhat Build OF Keycloak31/7/20267/8/2026
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group…
ModificadaMedia (4.9)0.42%—Redhat Build OF Keycloak31/7/202616/9/2026
A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child…
Pendiente de análisisAlta (7.5)0.63%—ComfyuiAI31/7/20268/9/2026
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt…
Pendiente de análisisAlta (8.2)0.40%—ComfyuiAI31/7/20268/9/2026
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and…
Pendiente de análisisAlta (7.5)0.97%—ComfyuiAI31/7/20268/9/2026
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated remote attacker to use traversal,…
Pendiente de análisisAlta (8.2)0.40%—ComfyuiAI31/7/20268/9/2026
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI…
AnalizadaMedia (6.4)0.99%—Amazon Amplify Codegen UI30/7/202610/8/2026
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to…
AplazadaMedia (6.1)0.18%—Ecommerce Fruits BazarAI30/7/20261/10/2026
Ecommerce Fruits Bazar 1.0 es vulnerable a Cross Site Scripting (XSS) en admin/edit_product.PHP.
AplazadaCrítica (9.8)0.39%—Ecommerce-project-with-php-and-mysqli-fruits-bazarAI30/7/20261/10/2026
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 es vulnerable a inyección SQL en /show_price_by_pdtId.php.
AnalizadaMedia (6.1)0.27%—IBM Engineering Requirements Management Doors WEB Access30/7/202629/9/2026
IBM Engineering Requirements Management DOORS y DOORS Web Access 9.7.2.1 hasta 9.7.2.11, y 9.6.1.1 hasta 9.6.1.13 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un atacante no autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista…