Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
–

2139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.34%—Headless Single Sign ONAI13/8/202614/8/2026
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Pendiente de análisisMedia (6.8)0.52%—Openstack DesignateAI12/8/20269/9/2026
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path.…
Pendiente de análisisCrítica (9.6)0.53%—Openstack DesignateAI12/8/20269/9/2026
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that…
AplazadaCrítica (9.8)0.67%—Formidable Digital SignaturesAI11/8/202612/8/2026
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled…
Pendiente de análisisAlta (7)0.16%—AMD Power Design ManagerAI11/8/202629/9/2026
A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.
AplazadaMedia (6.5)0.34%—Humansignal Label StudioAI11/8/20263/9/2026
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use…
AplazadaMedia (5.3)0.48%—Opensignlabs OpensignAI11/8/20263/9/2026
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal…
AplazadaAlta (7.5)0.61%—Opensignlabs OpensignAI11/8/20263/9/2026
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or…
AplazadaAlta (7.5)0.54%—Opensignlabs OpensignAI11/8/20263/9/2026
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An…
AplazadaAlta (7.5)0.25%—Opensignlabs OpensignAI11/8/20263/9/2026
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing…
AplazadaAlta (7.5)0.61%—Opensignlabs OpensignAI11/8/20263/9/2026
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the…
Pendiente de análisisMedia (5.3)0.29%—Axis Signed Video FrameworkAI11/8/20263/9/2026
The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.
AplazadaAlta (7.5)0.44%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and…
AplazadaAlta (7.5)0.65%—Opensignlabs OpensignserverAI10/8/202626/8/2026
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is…
AplazadaAlta (7.5)0.53%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records…
AplazadaAlta (7.5)0.61%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session…
AplazadaCrítica (9.8)0.50%—Single Sign ON FOR TNGAI10/8/202626/8/2026
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
AplazadaMedia (5.4)0.24%—Revenue Administration Turkiye E-signatureAI7/8/202626/8/2026
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.
AplazadaAlta (7.5)0.39%—Formidable Forms Signature Online Contract AutomationAI6/8/202612/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
AplazadaCrítica (9.8)0.48%—Kadence Woocommerce Email DesignerAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
ModificadaAlta (8.1)0.46%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on5/8/202631/8/2026
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user…
ModificadaAlta (8.1)0.46%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on5/8/202631/8/2026
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into…
Pendiente de análisisMedia (6.9)0.29%—HP DesignjetAI3/8/20263/8/2026
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.
AplazadaCrítica (9.8)0.89%💥 PoCSingle Sign ON FOR TNGAI1/8/202612/8/2026
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication —…
AplazadaCrítica (9.8)0.56%—Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI31/7/202626/8/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.