Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
5404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.33% | — | Solax CloudAI | 10/9/2025 | 30/9/2026 | Mediante el suministro de nombres de usuario, SolaX Cloud sugerirá cuentas de usuario (similares) y, de este modo, filtrará información sensible como direcciones de correo electrónico de los usuarios y números de teléfono. | |
| Modificada | Baja (3.5) | 0.26% | — | Quantumcloud Wpbot | 9/9/2025 | 17/6/2026 | The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.5) | 0.40% | — | Cloud Saml SSOAI | 6/9/2025 | 17/6/2026 | The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated attackers to delete any configured IdP,… | |
| Aplazada | Alta (8.2) | 0.28% | — | Cloud Saml SSOAI | 6/9/2025 | 17/6/2026 | The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads client-supplied POST parameters for organization… | |
| Aplazada | Media (5.9) | 0.18% | — | Thomas Harris Search Cloud ONEAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud One: from n/a through <= 2.2.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Givecloud Donation Forms WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9. | |
| Analizada | Media (6.5) | 0.83% | 💥 Exploit | @astrojs/cloudflare | 5/9/2025 | 17/6/2026 | Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives,… | |
| Analizada | Crítica (9) | 51% | ⚠ Explotación activa💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0. | |
| Analizada | Alta (7.5) | 6.5% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4. | |
| Analizada | Crítica (9.8) | 19% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform… | |
| Analizada | Alta (8.8) | 1.6% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4. | |
| Aplazada | Alta (8.6) | 0.35% | — | Akinsoft OctocloudAI | 2/9/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass. This issue affects OctoCloud: from s1.09.03 before v1.11.01. | |
| Aplazada | Media (4.7) | 0.15% | — | Akinsoft OctocloudAI | 2/9/2025 | 17/6/2026 | Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsing. This issue affects OctoCloud: from s1.09.01 before v1.11.01. | |
| Aplazada | Media (4.3) | 0.19% | — | Akinsoft OctocloudAI | 2/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft OctoCloud allows Cross-Site Scripting (XSS). This issue affects OctoCloud: from s1.09.01 before v1.11.01. | |
| Aplazada | Media (4.7) | 0.24% | — | Akinsoft OctocloudAI | 2/9/2025 | 30/9/2026 | La vulnerabilidad de elusión de autorización a través de clave controlada por el usuario en Akinsoft OctoCloud permite la exposición de fuga de recursos. Este problema afecta a OctoCloud: desde s1.09.02 antes de v1.11.01. | |
| Aplazada | Alta (7.8) | 1.1% | — | Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI | 2/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to… | |
| Analizada | Crítica (9.8) | 0.39% | — | Watsonx Orchestrate Cartridge FOR IBM Cloud PAK FOR Data | 30/8/2025 | 17/6/2026 | IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Aplazada | Alta (7.8) | 0.13% | — | Acronis Cyber Protect Cloud AgentAI | 28/8/2025 | 25/9/2026 | Escalada de privilegios local debido a permisos de carpeta inseguros. Los siguientes productos están afectados: Acronis Cyber Protect Cloud Agent (Windows) anterior a la compilación 40734. | |
| Analizada | Media (5.4) | 0.18% | — | Watson Assistant FOR IBM Cloud PAK FOR Data | 28/8/2025 | 26/9/2026 | IBM Watson Studio en Cloud Pak for Data 4.0 y 5.0 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría llevar a la divulgación de credenciales dentro de una… | |
| Aplazada | Alta (7.3) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 28/8/2025 | 17/6/2026 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40296. | |
| Analizada | Media (5.8) | 0.39% | — | Lumasoft Fotoshare Cloud | 27/8/2025 | 17/6/2026 | Validación de contraseña del lado del cliente (CWE-602) en lumasoft fotoShare Cloud 2025-03-13 que permite a atacantes no autenticados ver álbumes de fotos protegidos con contraseña. | |
| Analizada | Baja (2) | 0.30% | — | Kodcloud Kodbox | 25/8/2025 | 17/6/2026 | Se encontró una vulnerabilidad en kalcaddle kodbox 1.61. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /?explorer/upload/serverDownload del componente "Descargar desde el controlador de enlaces". La manipulación del argumento URL provoca Server-Side Request Forgery. El ataque puede ejecutarse… | |
| Aplazada | Crítica (10) | 0.68% | — | Google Cloud DataformAINPMAI | 25/8/2025 | 17/6/2026 | Una vulnerabilidad de Path Traversal en el proceso de instalación de paquetes NPM de Google Cloud Dataform permite a un atacante remoto leer y escribir archivos en los repositorios de otros clientes a través de un archivo package.json manipulado con fines malintencionados. | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Vulnerabilidad de asignación incorrecta de privilegios en quantumcloud Simple Business Directory Pro permite la escalada de privilegios. Este problema afecta a Simple Business Directory Pro: de n/d a n/d. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Link DirectoryAI | 20/8/2025 | 17/6/2026 | Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') en quantumcloud Simple Link Directory permite XSS reflejado. Este problema afecta a Simple Link Directory desde de n/d a n/d. |