Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.81% | — | Apache Nifi | 3/8/2026 | 5/8/2026 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and… | |
| Analizada | Alta (7.7) | 0.45% | — | Apache Nifi | 3/8/2026 | 10/8/2026 | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with… | |
| Aplazada | Baja (2.1) | 0.39% | — | Langgenius DifyAIPocoo Jinja2AI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine.… | |
| Analizada | Alta (7.8) | 0.16% | — | Dell Monitor Driver | 3/8/2026 | 7/8/2026 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Alta (8.5) | 0.20% | — | Teleniasoftware TvoxAI | 3/8/2026 | 9/9/2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The… | |
| Aplazada | Alta (8.6) | 2.4% | — | Teleniasoftware TvoxAI | 3/8/2026 | 9/9/2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action… | |
| Aplazada | Crítica (9.3) | 0.83% | — | Teleniasoftware TvoxAI | 3/8/2026 | 9/9/2026 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Elearningfreak Insert OR Embed Articulate ContentAI | 3/8/2026 | 26/8/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers… | |
| Aplazada | Media (5.3) | 0.71% | — | Support GenixAI | 1/8/2026 | 26/8/2026 | The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server. | |
| Aplazada | Baja (3.8) | 0.26% | — | Wpmanageninja Fluent SupportAI | 1/8/2026 | 26/8/2026 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope. | |
| Aplazada | Media (6.2) | 0.19% | — | Gemini-bridgeAI | 31/7/2026 | 10/9/2026 | gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI.… | |
| Aplazada | Alta (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 31/7/2026 | 31/8/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |
| Aplazada | Media (5.4) | 0.40% | — | OnionshareAI | 31/7/2026 | 10/9/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where… | |
| Aplazada | Media (4.8) | 0.34% | — | OnionshareAI | 31/7/2026 | 10/9/2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 31/7/2026 | 26/8/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115. | |
| Aplazada | Alta (8.8) | 1.2% | — | Realtyna Organic IDXAI | 31/7/2026 | 12/8/2026 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing… | |
| Aplazada | Crítica (9.8) | 0.50% | — | ShopmonitorAI | 31/7/2026 | 26/8/2026 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator… | |
| Aplazada | Baja (3.7) | 0.26% | — | Support GenixAI | 31/7/2026 | 26/8/2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments. | |
| Aplazada | Crítica (9.8) | 4.0% | 💥 Exploit | Realtyna Organic IDXAIRealtyna WPL Real EstateAI | 31/7/2026 | 12/8/2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by… | |
| Aplazada | Alta (8.1) | 0.29% | — | Miniorange 2FAAI | 31/7/2026 | 26/8/2026 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | CodeigniterAI | 31/7/2026 | 8/9/2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible… | |
| Aplazada | Alta (7.5) | 0.64% | — | CodeigniterAI | 31/7/2026 | 8/9/2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes… | |
| Aplazada | Crítica (9.4) | 0.61% | — | CodeigniterAI | 31/7/2026 | 8/9/2026 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path.… | |
| Aplazada | Media (4.8) | 0.17% | — | CodeigniterAI | 31/7/2026 | 8/9/2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may… | |
| Aplazada | Media (6.1) | 0.34% | — | Adonisjs Http ServerAI | 30/7/2026 | 10/9/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled… |