Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.34% | — | Mementor Text TO Speech FOR WPAI | 4/4/2026 | 21/7/2026 | The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry`… | |
| Aplazada | Baja (2.1) | 0.40% | — | TextpatternAI | 2/4/2026 | 24/7/2026 | A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt_uploadImage of the file rpc/TXP_RPCServer.php of the component XML-RPC Handler. The manipulation of the argument file.name leads to path traversal. Remote exploitation of the attack is possible. The… | |
| Pendiente de análisis | Alta (7.6) | 0.80% | — | Agentic-context-engineAI | 31/3/2026 | 25/7/2026 | A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the… | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | Opentext IDM Scim DriverAI | 27/3/2026 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1.0.1.0300 and… | |
| Pendiente de análisis | Alta (8.4) | 0.29% | — | Opentext Identity ManagerAI | 27/3/2026 | 7/10/2026 | Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1). | |
| Analizada | Crítica (9.8) | 3.6% | 💥 PoC | Dbashford Textract | 25/3/2026 | 17/6/2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization | |
| Aplazada | Media (6.4) | 0.41% | — | Text ToggleAI | 21/3/2026 | 17/6/2026 | The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, in… | |
| Aplazada | Media (6.4) | 0.33% | — | Image ALT Text ManagerAI | 21/3/2026 | 17/6/2026 | The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.8.2. This is due to insufficient input sanitization and output escaping when dynamically generating image alt and title attributes using a DOM parser. This makes it… | |
| Analizada | Media (5.1) | 0.26% | — | Textpattern | 20/3/2026 | 17/6/2026 | Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into… | |
| Analizada | Alta (7.4) | 0.23% | — | Opentext Zenworks Service Desk | 18/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects… | |
| Aplazada | Media (5.3) | 0.31% | — | Ajay Contextual Related PostsAI | 18/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contextual Related Posts: from n/a through < 4.2.2. | |
| Aplazada | Media (5.4) | 0.28% | — | TextmetricsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.4. | |
| Analizada | Media (5.1) | 0.30% | — | Opentext Vertica | 13/3/2026 | 17/6/2026 | Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X. | |
| Analizada | Media (5.1) | 0.18% | — | Opentext Vertica | 13/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from… | |
| Analizada | Media (5.1) | 0.18% | — | Opentext Vertica | 13/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS. The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from… | |
| Aplazada | Media (6.4) | 0.16% | — | Media Library ALT Text EditorAI | 7/3/2026 | 17/6/2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (8.3) | 0.56% | — | Opentext Filr | 3/3/2026 | 17/6/2026 | Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2. | |
| Analizada | Alta (7.5) | 0.40% | — | FKA Textream | 2/3/2026 | 17/6/2026 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state to all connected clients every 100 ms, an attacker can exhaust CPU and memory by flooding the server with connections,… | |
| Analizada | Alta (7.6) | 0.18% | — | FKA Textream | 2/3/2026 | 17/6/2026 | Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser session can silently… | |
| Analizada | Media (6.4) | 0.45% | — | Lfprojects Model Context Protocol Servers | 26/2/2026 | 17/6/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that file paths provided in the files argument were within the repository boundaries. Because the tool used GitPython's… | |
| Aplazada | Alta (8.6) | 0.15% | — | Opentext Carbonite Safe Server BackupAI | 24/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows Code Injection. The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6.8.3. | |
| Analizada | Media (5.3) | 0.25% | — | Opentext Directory Services | 19/2/2026 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from… | |
| Analizada | Alta (7.5) | 0.21% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to… | |
| Analizada | Media (5.3) | 0.17% | — | Opentext XM FAX | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery. The vulnerability could allow an attacker to perform blind SSRF to other systems accessible from the XM Fax server. This issue affects XM Fax: 24.2. | |
| Analizada | Alta (7.1) | 0.32% | — | Opentext XM FAX | 19/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal. The vulnerability could allow an attacker to arbitrarily disclose content of files on the local filesystem. This issue affects XM Fax: 24.2. |