Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.63% | — | Perl Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached… | |
| Aplazada | Alta (7.5) | 0.63% | — | Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`.… | |
| Aplazada | Alta (7.8) | 0.84% | — | Tubitak Bilgem Pardus-updateAI | 23/7/2026 | 23/7/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0. | |
| Aplazada | Alta (7.5) | 0.63% | — | Http DateAI | 17/7/2026 | 12/8/2026 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$`… | |
| Aplazada | Media (5.9) | 0.15% | — | ABB KNX Update ToolAIBJE KNX Update ToolAI | 17/7/2026 | 17/7/2026 | Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175. | |
| Aplazada | Alta (8.3) | 0.19% | — | Capgo Capacitor UpdaterAI | 10/7/2026 | 10/7/2026 | In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a… | |
| Aplazada | Media (5.3) | 0.47% | — | Bulk Order Update FOR WoocommerceAI | 8/7/2026 | 8/7/2026 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST… | |
| Aplazada | Crítica (9.1) | 0.61% | — | Owncloud CoreAIOwncloud UpdaterAI | 6/7/2026 | 30/9/2026 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute… | |
| Aplazada | Alta (7.8) | 0.14% | — | Tubitak Bilgem Pardus UpdateAI | 5/7/2026 | 6/7/2026 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6. | |
| Aplazada | Alta (8.5) | 0.15% | — | Expressupdate AgentAI | 26/6/2026 | 26/6/2026 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges. | |
| Modificada | Crítica (9.2) | 6.5% | — | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Aplazada | Alta (7.1) | 0.18% | — | Sweetdate CoreAI | 17/6/2026 | 5/10/2026 | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Order Delivery DateAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.10% | — | SwupdateAI | 3/6/2026 | 22/7/2026 | SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update. | |
| Aplazada | Media (6.4) | 0.32% | — | Image Attributes From Filename With Bulk UpdaterAI | 2/6/2026 | 22/7/2026 | The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.35% | — | Datenverwurstungszentrale Shariff WrapperAI | 28/5/2026 | 17/6/2026 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.35% | — | Easyupdatesmanager Easy Updates ManagerAI | 28/5/2026 | 17/6/2026 | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web… | |
| Aplazada | Media (4.3) | 0.27% | — | Prasadkirpekar WP Meta AND Date RemoverAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6. | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 26/5/2026 | 2/10/2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds… | |
| Modificada | Crítica (9.2) | 2.7% | — | F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+8 | 22/5/2026 | 25/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple… | |
| Modificada | Media (6.5) | 0.57% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 21/5/2026 | 1/9/2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to… | |
| Modificada | Media (6.5) | 0.58% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 20/5/2026 | 1/9/2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service… | |
| Analizada | Crítica (9.8) | 0.49% | — | Date Ical Project Date Ical | 19/5/2026 | 23/7/2026 | Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15. | |
| Aplazada | Alta (8.2) | 0.50% | — | Date Menu OF News ArticlesAI | 19/5/2026 | 17/6/2026 | The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the… | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… |