Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 51 respecto a la semana anterior
Críticas / altas1373▲ 40 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
575 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.6) | 0.52% | — | Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users… | |
| Pendiente de análisis | Alta (7.3) | 0.38% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete… | |
| Pendiente de análisis | Alta (7.3) | 0.32% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation… | |
| Pendiente de análisis | Alta (7.6) | 0.40% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the… | |
| Pendiente de análisis | Crítica (9.1) | 0.77% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Easy Integration FOR DropboxAI | 4/8/2026 | 26/8/2026 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account… | |
| Aplazada | Alta (7.5) | 1.2% | — | Bitintegrations BIT IntegrationsAI | 1/8/2026 | 12/8/2026 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Analizada | Crítica (9.8) | 0.85% | — | IBM Webmethods Integration | 30/7/2026 | 10/8/2026 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | |
| Aplazada | Media (4.3) | 0.39% | — | Advancedformintegration Advanced Form IntegrationAI | 28/7/2026 | 28/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.46% | — | Miniorange Discord IntegrationAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Retail Integration BUS | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Retail Integration BUS | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful… | |
| Aplazada | Media (4.4) | 0.41% | — | Lockme Oauth2 Calendars IntegrationAI | 11/7/2026 | 13/7/2026 | The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,… | |
| Aplazada | Alta (8.1) | 0.37% | — | Advancedformintegration Advanced Form IntegrationAI | 1/7/2026 | 1/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public… | |
| Modificada | Media (5.5) | 0.27% | — | IBM APP Connect EnterpriseIBM Integration BUS | 30/6/2026 | 20/7/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. | |
| Aplazada | Media (6.5) | 0.50% | — | Bitapps BIT IntegrationsAI | 19/6/2026 | 23/6/2026 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI | 16/6/2026 | 1/10/2026 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 HubspotAI | 15/6/2026 | 8/7/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Salesforce IntegrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Contact Form 7 AND Constant ContactAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Keap Infusionsoft IntegrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Advancedformintegration Advanced Form IntegrationAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. |