Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
21.645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.80% | 💥 PoC | Rrrene Htmlsanitizeex | 6/8/2026 | 19/8/2026 | Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1 matches the property name with an unbounded… | |
| Modificada | Baja (2.3) | 0.45% | — | Rrrene Htmlsanitizeex | 6/8/2026 | 19/8/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a page served to other users.… | |
| Modificada | Baja (2.3) | 0.51% | — | Rrrene Htmlsanitizeex | 6/8/2026 | 19/8/2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object> element in sanitized HTML. object is the one URI-bearing element in… | |
| Modificada | Baja (2.3) | 0.57% | — | Rrrene Htmlsanitizeex | 6/8/2026 | 19/8/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps… | |
| Modificada | Media (4.8) | 0.40% | — | Rrrene Htmlsanitizeex | 6/8/2026 | 19/8/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the form and formaction attributes on an… | |
| Aplazada | Alta (7.3) | 0.30% | — | Staff TrainingAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpmanageninja Ninja TablesAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Yithemes Yith Woocommerce Zoom MagnifierAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | |
| Aplazada | Alta (8.7) | 1.6% | — | Sonic 3 A I RAI | 6/8/2026 | 24/9/2026 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is… | |
| Aplazada | Alta (8.3) | 0.17% | — | Sonic 3 AIRAI | 6/8/2026 | 24/9/2026 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An… | |
| Analizada | Crítica (9.8) | 0.48% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 10/8/2026 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This… | |
| Analizada | Media (4.4) | 0.16% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 12/8/2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such… | |
| Analizada | Media (4.9) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 13/8/2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client… | |
| Analizada | Alta (7.5) | 0.41% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 9/8/2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the… | |
| En análisis | Media (5.8) | 0.29% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+3 | 6/8/2026 | 9/8/2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious… | |
| Aplazada | Media (6.5) | 0.18% | — | Miniorange Google AuthenticatorAI | 6/8/2026 | 26/8/2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | |
| Analizada | Crítica (10) | 0.59% | ⚠ Explotación activa💥 PoC | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 25/9/2026 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result… | |
| Analizada | Crítica (9.4) | 0.67% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 6/8/2026 | 29/9/2026 | El script de autenticación condicional (autenticación adaptativa) no aplica correctamente la finalización de todos los pasos de autenticación requeridos cuando se configura un patrón específico de múltiples pasos que involucra ciertos autenticadores. Esto permite a un atacante eludir los desafíos de autenticación… | |
| Analizada | Media (5.4) | 0.14% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 6/8/2026 | 29/9/2026 | El procesador Ajax dentro de la consola Carbon no protege adecuadamente las operaciones que cambian el estado de ataques de falsificación de petición en sitios cruzados (CSRF). Específicamente, utiliza el método HTTP GET para estas operaciones, y aunque el atributo de cookie SameSite=Lax se emplea para la mitigación,… | |
| Pendiente de análisis | Media (5.6) | 0.11% | — | Elan Microelectronics Corp Elan Smart-padAIElan Microelectronics Corp Etd.sysAIElan Microelectronics Corp Etdsmbus.sysAI | 6/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where… | |
| Aplazada | Alta (7.2) | 0.53% | — | Wpmanageninja FluentsmtpAI | 6/8/2026 | 12/8/2026 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | National Instruments Ni-palAIMicrosoft WindowsAI | 5/8/2026 | 28/8/2026 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Qualys Container Scanning ConnectorAI | 5/8/2026 | 31/8/2026 | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Analizada | Media (6.5) | 0.64% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 5/8/2026 | 16/9/2026 | — | |
| Analizada | Alta (8.8) | 0.73% | 💥 PoC | Cisco Unified Computing System | 5/8/2026 | 31/8/2026 | — |