Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
21.646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.15% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 9/9/2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |
| Aplazada | Alta (7.8) | 0.15% | 💥 PoC | Unistal Systems PVT LTD Protegent 360AI | 23/7/2026 | 30/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Pendiente de análisis | Crítica (9.8) | 1.9% | 💥 PoC | Miniorange Saml Single Sign ONAI | 23/7/2026 | 24/7/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return… | |
| Analizada | Media (5.3) | 0.29% | — | Apple Swiftnio Http/2 | 23/7/2026 | 1/9/2026 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0. | |
| Aplazada | Media (5.2) | 0.24% | — | Tridium Niagara FrameworkAITridium Niagara Enterprise SecurityAI | 23/7/2026 | 23/7/2026 | Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before… | |
| Analizada | Alta (7.7) | 0.11% | — | Apple Swiftnio SSL | 23/7/2026 | 4/9/2026 | NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpsocialninja WP Social NinjaAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpmanageninja Ninja TablesAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpmanageninja Fluent SupportAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Miniorange Discord IntegrationAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Knitpay Knit PAYAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | |
| Aplazada | Alta (7.5) | 0.53% | — | Security Ninja PremiumAI | 23/7/2026 | 23/7/2026 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor… | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Media (5.5) | 0.14% | 💥 PoC | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 | |
| Aplazada | Alta (8.8) | 0.66% | — | ZipgeniusAI | 22/7/2026 | 6/10/2026 | Un problema en ZipGenius Team ZipGenius v.6.3.2.3116 y versiones anteriores permite a un atacante remoto escalar privilegios y ejecutar código arbitrario a través del zipgenius.exe. | |
| Pendiente de análisis | Baja (3.3) | 0.13% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's… | |
| Aplazada | Media (6.5) | 0.36% | 💥 PoC | Universe Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI | 22/7/2026 | 5/8/2026 | Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026. | |
| Aplazada | Baja (1.3) | 1.5% | — | Qusetions Minicode-pythonAI | 22/7/2026 | 22/7/2026 | A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is… | |
| Analizada | Media (6.3) | 0.27% | — | Oracle Learning Management | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle Learning Management | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful… | |
| Analizada | Alta (7.5) | 0.15% | — | Oracle Communications Converged Application Server | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Communications Converged Application Server | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications… |