Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.68% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 16/8/2026 | 20/8/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.37% | — | Simply Schedule AppointmentsAI | 15/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users. | |
| Analizada | Crítica (9.4) | 0.55% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | |
| Analizada | Media (5.3) | 0.59% | — | IBM Websphere Application Server | 13/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled. | |
| Aplazada | Alta (7.5) | 0.42% | — | Woocommerce AppointmentsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | |
| Analizada | Alta (8.1) | 0.42% | — | IBM Websphere Application Server | 12/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Analizada | Alta (8.3) | 0.14% | 💥 PoC | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Websphere Application Server | 5/8/2026 | 10/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 26/8/2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can read, edit, or delete another company's… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 28/8/2026 | Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Menulux Software INC Mobile APPAI | 3/8/2026 | 26/8/2026 | Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026. | |
| Aplazada | Media (6.5) | 0.34% | — | Simply Schedule AppointmentsAI | 3/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,… | |
| Aplazada | Alta (7.5) | 0.41% | 💥 PoC | Simply Schedule AppointmentsAI | 2/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. | |
| Analizada | Alta (8.5) | 0.58% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. | |
| Analizada | Alta (7.5) | 0.56% | — | IBM Websphere Application Server | 30/7/2026 | 12/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 5/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | |
| Analizada | Alta (8.8) | 0.43% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. |