Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
–

21.646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.15%—Openstack Ironic Python AgentAI24/7/20269/9/2026
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
AplazadaAlta (7.8)0.15%💥 PoCUnistal Systems PVT LTD Protegent 360AI23/7/202630/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
Pendiente de análisisCrítica (9.8)1.9%💥 PoCMiniorange Saml Single Sign ONAI23/7/202624/7/2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return…
AnalizadaMedia (5.3)0.29%—Apple Swiftnio Http/223/7/20261/9/2026
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
AplazadaMedia (5.2)0.24%—Tridium Niagara FrameworkAITridium Niagara Enterprise SecurityAI23/7/202623/7/2026
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before…
AnalizadaAlta (7.7)0.11%—Apple Swiftnio SSL23/7/20264/9/2026
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is…
AplazadaMedia (5.3)0.33%—Wpsocialninja WP Social NinjaAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
AplazadaMedia (5.3)0.33%—Wpmanageninja Ninja TablesAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
AplazadaMedia (6.5)0.22%—Wpmanageninja Fluent SupportAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
AplazadaAlta (8.1)0.46%—Miniorange Discord IntegrationAI23/7/202623/7/2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
AplazadaCrítica (9.6)0.20%—Ninjaforms File Uploads ExtensionAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaMedia (6.5)0.33%—Knitpay Knit PAYAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
AplazadaAlta (7.1)0.25%—Wpforms Download MonitorAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
AplazadaAlta (7.5)0.53%—Security Ninja PremiumAI23/7/202623/7/2026
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor…
AplazadaAlta (7.8)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
AplazadaAlta (7.8)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
AplazadaMedia (5.5)0.14%💥 PoCUnistal Systems Pvt. LTD Protegent 360AI22/7/202624/7/2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
AplazadaAlta (8.8)0.66%—ZipgeniusAI22/7/20266/10/2026
Un problema en ZipGenius Team ZipGenius v.6.3.2.3116 y versiones anteriores permite a un atacante remoto escalar privilegios y ejecutar código arbitrario a través del zipgenius.exe.
Pendiente de análisisBaja (3.3)0.13%—Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI22/7/202622/7/2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's…
AplazadaMedia (6.5)0.36%💥 PoCUniverse Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI22/7/20265/8/2026
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026.
AplazadaBaja (1.3)1.5%—Qusetions Minicode-pythonAI22/7/202622/7/2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is…
AnalizadaMedia (6.3)0.27%—Oracle Learning Management21/7/202617/8/2026
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful…
AnalizadaMedia (6.5)0.39%—Oracle Learning Management21/7/202619/8/2026
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful…
AnalizadaAlta (7.5)0.15%—Oracle Communications Converged Application Server21/7/202619/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Converged…
AnalizadaAlta (8.1)0.39%—Oracle Communications Converged Application Server21/7/202619/8/2026
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications…