Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

6574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.45%—Transloadit UppyAI14/4/202617/6/2026
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
AnalizadaAlta (8.1)0.28%—Fortinet Fortisoar14/4/202617/6/2026
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack…
AnalizadaMedia (6.5)0.26%—Fortinet Fortisoar14/4/202617/6/2026
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4…
AnalizadaMedia (6.5)0.27%—Fortinet Fortisoar14/4/202617/6/2026
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4…
AnalizadaMedia (6.5)0.42%—Fortinet Fortisoar14/4/202617/6/2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all…
AnalizadaAlta (7.5)0.17%—Fortinet Fortisoar14/4/20268/7/2026
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise…
AnalizadaMedia (5.4)0.22%—Fortinet Fortisoar14/4/202617/6/2026
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise…
AnalizadaMedia (6.5)0.15%—Fortinet Fortisoar14/4/20268/7/2026
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise…
AnalizadaMedia (4.3)0.20%—Fortinet Fortisoar14/4/202617/6/2026
A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6.0 through 7.6.2,…
AnalizadaMedia (4.8)0.38%—Redhat Build OF Keycloak14/4/202617/6/2026
A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed into an inline…
AplazadaBaja (1.9)1.4%—Aandrew-me YtdownloaderAI13/4/202617/6/2026
A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.3)0.45%—Aandrew-me YtdownloaderAI13/4/202617/6/2026
A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure.
AplazadaMedia (6.2)0.17%💥 PoCTinyobjloaderAI13/4/202617/6/2026
A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.
En análisisAlta (7.2)0.23%—Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar13/4/20267/7/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
AnalizadaBaja (2)0.18%—Paloaltonetworks Autonomous Digital Experience Manager13/4/20267/7/2026
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
AnalizadaMedia (4)0.15%—Paloaltonetworks Cortex XDR Agent13/4/20267/7/2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
AplazadaMedia (4.3)0.36%—Download ManagerAI10/4/202617/6/2026
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without…
AplazadaCrítica (9.1)0.70%💥 PoCV2boardAITIM Mann XboardAI9/4/202614/7/2026
V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unauthenticated attackers can POST to the loginWithMailLink endpoint with a known email address to receive the full…
AnalizadaMedia (5.4)0.32%—Pyload9/4/202617/6/2026
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execute MODIFY operations…
AplazadaMedia (6.4)0.35%—Download ManagerAI9/4/202624/7/2026
El plugin Download Manager para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del parámetro 'sid' del shortcode 'wpdm_members' en versiones hasta la 3.3.52 inclusive. Esto se debe a una sanitización de entrada insuficiente y un escape de salida deficiente en el atributo del shortcode 'sid'…
AplazadaMedia (4.4)0.33%—Experto DashboardAI9/4/202624/7/2026
El plugin Experto Dashboard for WooCommerce para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los campos de configuración del plugin (incluyendo 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size' y 'Text Font Weight') en todas las…
AnalizadaAlta (7.5)0.35%—Openairinterface Oai-cn5g-amf8/4/202625/7/2026
OpenAirInterface v2.2.0 acepta el Modo de Seguridad Completo sin ninguna protección de integridad. La configuración ha soportado integridad NIA1 y NIA2. Pero si un UE envía una solicitud de registro inicial con solo la capacidad de seguridad IA0, OpenAirInterface acepta y procede. Este contexto de seguridad degradado…
AnalizadaAlta (7.5)0.66%—Openairinterface Oai-cn5g-amf8/4/202625/7/2026
OpenAirInterface Versión 2.2.0 tiene una vulnerabilidad de desbordamiento de búfer al procesar UplinkNASTransport que contiene una Respuesta de Autenticación que contiene una PDU NAS con una respuesta de tamaño excesivo (por ejemplo, 100 bytes). La respuesta es decodificada por el AMF y pasada al componente AUSF para…
AplazadaMedia (5.3)0.26%💥 PoCShahjada Download ManagerAI8/4/202620/7/2026
Vulnerabilidad por falta de autorización en Shahjada Download Manager download-manager permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Download Manager: desde n/a hasta <= 3.3.52.
AplazadaMedia (5.3)0.29%—Dfactory Download AttachmentsAI8/4/202624/7/2026
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en dFactory Download Attachments download-attachments permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Download Attachments: desde n/a hasta <= 1.4.0.