Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.46%—Xnau Participants DatabaseAI1/8/202626/8/2026
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
AplazadaAlta (7.5)0.55%—Artica ProxyAI28/7/202630/7/2026
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session…
AnalizadaMedia (6.5)0.39%—Jfrog Artifactory27/7/202630/7/2026
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability…
AnalizadaAlta (7.2)0.57%—Jfrog Artifactory27/7/202630/7/2026
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
AnalizadaAlta (8.8)0.64%—Jfrog Artifactory27/7/202615/9/2026
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
AnalizadaMedia (6.5)0.35%—Jfrog Artifactory27/7/202630/7/2026
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
AnalizadaMedia (6.5)0.41%—Jfrog Artifactory27/7/202630/7/2026
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and…
AnalizadaMedia (6.8)0.31%—Jfrog Artifactory27/7/202630/7/2026
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
AnalizadaMedia (5.4)0.31%—Jfrog Artifactory27/7/202630/7/2026
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
AnalizadaAlta (8.8)0.59%—Jfrog Artifactory27/7/202630/7/2026
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
AnalizadaMedia (6.5)0.35%—Jfrog Artifactory27/7/202630/7/2026
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
AnalizadaAlta (8.8)0.65%—Jfrog Artifactory27/7/202630/7/2026
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
AnalizadaAlta (8.8)0.37%💥 PoCJfrog Artifactory27/7/202630/7/2026
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
AnalizadaAlta (8.8)0.52%—Jfrog Artifactory27/7/202630/7/2026
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
AnalizadaAlta (8.8)8.6%⚠ Explotación activaJfrog Artifactory27/7/202612/9/2026
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
AplazadaMedia (5.3)0.42%—Xnau Participants DatabaseAI24/7/202624/7/2026
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing…
AplazadaCrítica (10)0.60%—Xnau Participants DatabaseAI23/7/202623/7/2026
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
AplazadaCrítica (9.3)0.40%—Xnau Participants DatabaseAI23/7/202623/7/2026
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
AplazadaMedia (4.3)0.25%—Xnau Participants DatabaseAI23/7/202623/7/2026
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
AplazadaAlta (7.5)0.42%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202628/7/2026
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it…
AplazadaAlta (7.5)0.43%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202627/7/2026
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,…
AplazadaMedia (6.5)0.42%—Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
AplazadaCrítica (9.1)0.43%—Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the…
AplazadaBaja (1.9)0.15%—Minitool Partition WizardAI12/7/202613/7/2026
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the…
AnalizadaMedia (4.8)0.22%—Artificial Intelligence Project Artificial Intelligence10/7/202616/7/2026
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.