Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
21.644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.8% | — | Pronis Loisirs Billetterie CSEAI | 17/8/2026 | 9/9/2026 | Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code. | |
| Aplazada | Crítica (9.8) | 0.93% | — | Squirro Cognitive SearchAI | 17/8/2026 | 31/8/2026 | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. | |
| Aplazada | Media (6.1) | 0.31% | — | Squirro Cognitive SearchAI | 17/8/2026 | 9/9/2026 | Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Squirro Cognitive SearchAI | 17/8/2026 | 31/8/2026 | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. | |
| Aplazada | Alta (8.7) | 0.61% | — | Belledonne Communications Bcg729AI | 17/8/2026 | 24/9/2026 | Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundaries by sending a zero-length comfort-noise RTP payload. A zero-length payload… | |
| Aplazada | Crítica (9) | 0.41% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 17/8/2026 | 26/8/2026 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114. | |
| Pendiente de análisis | Crítica (9.4) | 0.34% | — | Google Chronicle SoarAI | 17/8/2026 | 31/8/2026 | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no… | |
| Aplazada | Media (6.5) | 0.55% | — | School Management Education Learning ERPAI | 16/8/2026 | 20/8/2026 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.4) | 0.33% | — | Yeken Snippet ShortcodesAI | 16/8/2026 | 20/8/2026 | The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.33% | — | Toocheke CompanionAI | 16/8/2026 | 20/8/2026 | The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_color' post meta field. This is due to insufficient input sanitization in the toocheke_series_bg_color_save() function (which stores the raw $_POST value in post meta) and… | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 15/8/2026 | 20/8/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Crítica (9.8) | 0.58% | — | User Session SynchronizerAI | 15/8/2026 | 20/8/2026 | The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation… | |
| Pendiente de análisis | Media (6.3) | 0.30% | — | Openstack IronicAI | 14/8/2026 | 1/9/2026 | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. | |
| Aplazada | Media (6) | 0.38% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |
| Aplazada | Alta (8.5) | 0.53% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |
| Aplazada | Media (5.3) | 0.40% | — | Cityboss E-municipalityAI | 14/8/2026 | 26/8/2026 | Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204. | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Devolutions Powershell UniversalAI | 14/8/2026 | 28/8/2026 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.37% | — | Enzovezzaro Mcp-dominican-layerAI | 13/8/2026 | 14/8/2026 | A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of the component PDF Parsing. Performing a manipulation of the argument pdfUrl results in server-side request forgery. It is possible to initiate the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Enzovezzaro Mcp-dominican-layerAI | 13/8/2026 | 18/8/2026 | A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is possible to be… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Signify Philips HUE Bridge PROAIEclipse MosquittoAI | 13/8/2026 | 26/8/2026 | The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010. | |
| Analizada | Media (6.5) | 0.17% | — | IBM Planning Analytics Local | 13/8/2026 | 17/8/2026 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Aplazada | Media (5.1) | 0.31% | — | Saurus CMS Community EditionAI | 13/8/2026 | 31/8/2026 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Ninja Tables PROAI | 13/8/2026 | 9/9/2026 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent… | |
| Pendiente de análisis | Media (5.1) | 0.55% | — | Rails Html SanitizerAI | 13/8/2026 | 18/9/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default… |