Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.46% | — | Xnau Participants DatabaseAI | 1/8/2026 | 26/8/2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Alta (7.5) | 0.55% | — | Artica ProxyAI | 28/7/2026 | 30/7/2026 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session… | |
| Analizada | Media (6.5) | 0.39% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability… | |
| Analizada | Alta (7.2) | 0.57% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access. | |
| Analizada | Alta (8.8) | 0.64% | — | Jfrog Artifactory | 27/7/2026 | 15/9/2026 | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. | |
| Analizada | Media (6.5) | 0.35% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | |
| Analizada | Media (6.5) | 0.41% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and… | |
| Analizada | Media (6.8) | 0.31% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions. | |
| Analizada | Media (5.4) | 0.31% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected. | |
| Analizada | Alta (8.8) | 0.59% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. | |
| Analizada | Media (6.5) | 0.35% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data. | |
| Analizada | Alta (8.8) | 0.65% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | |
| Analizada | Alta (8.8) | 0.37% | 💥 PoC | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. | |
| Analizada | Alta (8.8) | 0.52% | — | Jfrog Artifactory | 27/7/2026 | 30/7/2026 | An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. | |
| Analizada | Alta (8.8) | 8.6% | ⚠ Explotación activa | Jfrog Artifactory | 27/7/2026 | 12/9/2026 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | |
| Aplazada | Media (5.3) | 0.42% | — | Xnau Participants DatabaseAI | 24/7/2026 | 24/7/2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing… | |
| Aplazada | Crítica (10) | 0.60% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 28/7/2026 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it… | |
| Aplazada | Alta (7.5) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,… | |
| Aplazada | Media (6.5) | 0.42% | — | Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the… | |
| Aplazada | Baja (1.9) | 0.15% | — | Minitool Partition WizardAI | 12/7/2026 | 13/7/2026 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the… | |
| Analizada | Media (4.8) | 0.22% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. |