Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/8/2026 | 26/8/2026 | The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a… | |
| Analizada | Media (6) | 0.56% | — | Amazon AWS Software Development KIT | 12/8/2026 | 18/8/2026 | An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862. | |
| Analizada | Media (6) | 0.50% | — | Amazon AWS Software Development KIT | 12/8/2026 | 18/8/2026 | An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862. | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | SAP Abap Development ToolsAISAP Netweaver AS AbapAI | 11/8/2026 | 26/8/2026 | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper EmbedpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | |
| Aplazada | Baja (2.1) | 0.50% | — | Monomythdevelopment La-forge-mcpAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | |
| Pendiente de análisis | Alta (8.7) | 1.0% | — | Lamp Rapid Development PlatformAI | 4/8/2026 | 16/9/2026 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message… | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk FBX Software Development KIT | 4/8/2026 | 4/9/2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Aplazada | Media (5.8) | 0.33% | — | Wpdeveloper EmbedpressAI | 4/8/2026 | 26/8/2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are… | |
| Aplazada | Media (4.8) | 0.24% | — | Wpdeveloper Essential Addons FOR ElementorAI | 30/7/2026 | 30/7/2026 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed,… | |
| Pendiente de análisis | Crítica (9.3) | 0.22% | — | Agent Development KITAI | 29/7/2026 | 30/7/2026 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdeveloper BetterdocsAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Process Manufacturing Product Development | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (7) | 0.13% | — | Oracle Jdeveloper | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Process Manufacturing Product Development | 21/7/2026 | 4/8/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (7.5) | 0.28% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Analizada | Baja (3.7) | 0.27% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.… | |
| Analizada | Baja (3.1) | 0.22% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Baja (3.7) | 0.27% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Analizada | Media (4.8) | 0.22% | — | Oracle Jdeveloper | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… |