Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.34% | — | Adonisjs Http ServerAI | 30/7/2026 | 10/9/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled… | |
| Analizada | Alta (7.5) | 0.38% | — | IBM Planning Analytics Local | 30/7/2026 | 12/8/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. | |
| Aplazada | Alta (7.5) | 0.63% | — | Perl Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached… | |
| Aplazada | Alta (7.5) | 0.63% | — | Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`.… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (6.1) | 0.25% | — | Animation Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting. | |
| Aplazada | Alta (7.1) | 0.27% | — | LG Electronics SmartshareAIMicrosoft Windows 10AI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | |
| Pendiente de análisis | Alta (8.3) | 0.42% | — | Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Pendiente de análisis | Alta (7.5) | 0.74% | — | Aten UnizonAI | 29/7/2026 | 30/7/2026 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider… | |
| Analizada | Media (5.5) | 0.25% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Schneider-electric Igss DefinitionAI | 29/7/2026 | 30/7/2026 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. | |
| Aplazada | Media (4.3) | 0.19% | — | Facturacion Electronica Costa RicaAI | 29/7/2026 | 30/7/2026 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Social Login AND RegisterAI | 29/7/2026 | 30/7/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any… | |
| Pendiente de análisis | Media (6.3) | 0.26% | — | Tanium PatchAI | 28/7/2026 | 30/7/2026 | Tanium addressed a SQL injection vulnerability in Patch. | |
| Aplazada | Media (6.5) | 0.41% | — | Plugin OrganizerAI | 28/7/2026 | 28/7/2026 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient escaping on the user-supplied parameter in the perform_plugin_search() function, where esc_sql() output is passed as the replacement string… | |
| Analizada | Media (5.9) | 0.26% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| Analizada | Alta (8.6) | 0.25% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |
| Aplazada | Alta (8.8) | 0.37% | — | Universal Software INC UkbsAI | 28/7/2026 | 4/8/2026 | Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (6.9) | 0.67% | — | Ninenines CowboyAI | 28/7/2026 | 30/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in a map… | |
| Aplazada | Alta (8.7) | 0.51% | — | Ninenines CowlibAINinenines CowboyAIRabbitmqAI | 28/7/2026 | 30/7/2026 | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl… | |
| Aplazada | Media (5.3) | 0.38% | — | Nice-select2AI | 28/7/2026 | 30/7/2026 | Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact… | |
| Aplazada | Alta (7.1) | 0.25% | — | GetgenieAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. |