Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.47%—Tp-link Omada ControllerAI11/9/202611/9/2026
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized…
AplazadaMedia (6.9)0.67%—Tp-link Omada ControllerAI8/9/202621/9/2026
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the…
AplazadaAlta (8.6)1.1%—Laradashboard Lara DashboardAI7/9/202610/9/2026
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
AplazadaAlta (8.6)0.71%—Laradashboard Lara DashboardAI7/9/20268/9/2026
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified…
AplazadaCrítica (9.3)1.1%—Laradashboard Lara DashboardAI5/9/202618/9/2026
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to…
Pendiente de análisisMedia (6.7)0.12%—IBM QradarAI4/9/20268/9/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
AnalizadaAlta (8.5)0.14%—Hitachienergy Microscada X Sys6003/9/20269/9/2026
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
AnalizadaAlta (8.5)0.14%—Hitachienergy Microscada X Sys6003/9/20269/9/2026
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.
AnalizadaMedia (4.6)0.21%—Hitachienergy Microscada X Sys6003/9/20269/9/2026
A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a…
Pendiente de análisisAlta (8.1)0.16%—Progress Telerik UI FOR AjaxAIProgress RadaditorAI2/9/20268/9/2026
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into,…
AplazadaMedia (6.4)0.15%—AvadaAI28/8/202628/8/2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaAlta (8.5)0.55%—Open-metadata OpenmetadataAI26/8/202616/9/2026
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats…
AplazadaCrítica (9.8)0.92%💥 PoCAvadaAIAvada Fusion BuilderAI26/8/202627/8/2026
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it…
AplazadaCrítica (9.3)0.40%—ReadablerAI18/8/202620/8/2026
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
AplazadaMedia (4)0.18%—Adaguc ServerAI18/8/202618/9/2026
Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document whose geometry contains a malformed…
AplazadaMedia (6.5)0.38%—Astro Vercel AdapterAI17/8/20269/9/2026
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes…
AplazadaMedia (4.3)0.43%—Shortpixel Adaptive ImagesAI16/8/202620/8/2026
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AnalizadaMedia (6.1)0.28%—Scada-lts12/8/202625/8/2026
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
AnalizadaCrítica (9.9)0.52%—Scada-lts12/8/202625/8/2026
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS…
AnalizadaAlta (8.6)1.0%⚠ Explotación activaCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense11/8/202616/9/2026
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,…
Pendiente de análisisAlta (7.5)0.83%—Google Ml-metadataAI10/8/202621/9/2026
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could…
AplazadaMedia (5.5)0.47%—Uatech BadasoAI10/8/202613/8/2026
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AplazadaMedia (5.5)0.50%—Adafap Api-mcpAI9/8/202612/8/2026
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to…
AplazadaBaja (1.9)0.17%—Abracadabra50 Claude-seshAI9/8/202612/8/2026
A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called…
AnalizadaAlta (8.8)0.49%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.