Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.34% | — | Headless Single Sign ONAI | 13/8/2026 | 14/8/2026 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | |
| Pendiente de análisis | Media (6.8) | 0.52% | — | Openstack DesignateAI | 12/8/2026 | 9/9/2026 | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path.… | |
| Pendiente de análisis | Crítica (9.6) | 0.53% | — | Openstack DesignateAI | 12/8/2026 | 9/9/2026 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Formidable Digital SignaturesAI | 11/8/2026 | 12/8/2026 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled… | |
| Pendiente de análisis | Alta (7) | 0.16% | — | AMD Power Design ManagerAI | 11/8/2026 | 29/9/2026 | A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.34% | — | Humansignal Label StudioAI | 11/8/2026 | 3/9/2026 | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use… | |
| Aplazada | Media (5.3) | 0.48% | — | Opensignlabs OpensignAI | 11/8/2026 | 3/9/2026 | An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal… | |
| Aplazada | Alta (7.5) | 0.61% | — | Opensignlabs OpensignAI | 11/8/2026 | 3/9/2026 | An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or… | |
| Aplazada | Alta (7.5) | 0.54% | — | Opensignlabs OpensignAI | 11/8/2026 | 3/9/2026 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An… | |
| Aplazada | Alta (7.5) | 0.25% | — | Opensignlabs OpensignAI | 11/8/2026 | 3/9/2026 | An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing… | |
| Aplazada | Alta (7.5) | 0.61% | — | Opensignlabs OpensignAI | 11/8/2026 | 3/9/2026 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Axis Signed Video FrameworkAI | 11/8/2026 | 3/9/2026 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected. | |
| Aplazada | Alta (7.5) | 0.44% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and… | |
| Aplazada | Alta (7.5) | 0.65% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is… | |
| Aplazada | Alta (7.5) | 0.53% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records… | |
| Aplazada | Alta (7.5) | 0.61% | — | Opensignlabs OpensignserverAI | 10/8/2026 | 26/8/2026 | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Single Sign ON FOR TNGAI | 10/8/2026 | 26/8/2026 | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | |
| Aplazada | Media (5.4) | 0.24% | — | Revenue Administration Turkiye E-signatureAI | 7/8/2026 | 26/8/2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | HP DesignjetAI | 3/8/2026 | 3/8/2026 | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews. | |
| Aplazada | Crítica (9.8) | 0.89% | 💥 PoC | Single Sign ON FOR TNGAI | 1/8/2026 | 12/8/2026 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication —… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 31/7/2026 | 26/8/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115. |