Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

3320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.39%💥 PoCOrdasoft Osgallery SearchAIJoomlaAI20/9/202622/9/2026
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a…
AplazadaMedia (4.3)0.23%—Search Atlas SEOAI19/9/202621/9/2026
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (7.1)0.63%—Arcadedb-engineAI18/9/202622/9/2026
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is matched by exact equality and therefore does not cover its…
AplazadaMedia (5.3)0.35%—ArcadedbAI18/9/202618/9/2026
ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC 1918 or loopback IPv4 payloads to reach internal services and cloud metadata…
AplazadaMedia (5.3)0.29%—Arcadedb-engineAI18/9/202618/9/2026
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers have no current user, LocalDatabase.checkPermissionsOnFile…
AplazadaAlta (7.1)0.38%—ArcadedbAI18/9/202621/9/2026
ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to DatabaseContext, causing per-type and per-bucket ACL checks to silently no-op and allowing authenticated…
AplazadaAlta (7.1)0.44%—Arcadedb-engineAI18/9/202618/9/2026
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user…
AplazadaAlta (8.6)0.36%—ArcadedbAI18/9/202622/9/2026
ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by…
AplazadaMedia (5.5)1.4%—Marcopiovanello Yt-dlp-web-uiAI18/9/202622/9/2026
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has…
AnalizadaCrítica (9.8)0.53%—Microsoft Azure ARC17/9/202625/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.48%—Microsoft Azure ARC17/9/202625/9/2026
Azure Arc Elevation of Privilege Vulnerability
AplazadaCrítica (9.8)0.32%—Maildata Email Archiving SystemAI17/9/202622/9/2026
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
AplazadaAlta (7.2)0.59%—Lxc-ciAIArchlinux Arch LinuxAI17/9/202630/9/2026
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that…
AplazadaMedia (6.5)0.22%—JetsearchAI17/9/202619/9/2026
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
AplazadaAlta (8.7)0.52%—Manticore SearchAI16/9/202622/9/2026
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that…
AplazadaAlta (7.1)0.45%—ArcherysecAI16/9/202624/9/2026
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses,…
AplazadaAlta (7.1)0.48%—Zlt2000 Microservices-platformAIElasticsearchAI16/9/202618/9/2026
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (7.5)0.32%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…
AplazadaAlta (7.8)0.16%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle…
AplazadaAlta (7.8)0.12%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search…
AplazadaAlta (7.8)0.16%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search…
Orbitaley — Vulnerabilidades