Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9651 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.32%—Bosh Windows Stemcell BuilderAI9/7/20269/7/2026
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Pendiente de análisisAlta (8.5)0.15%—Bosh-ecosystem Bosh-windows-stemcell-builderAI9/7/20269/7/2026
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected…
AplazadaAlta (8.8)0.44%—Elegantthemes Divi Form BuilderAI9/7/20269/7/2026
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and…
AplazadaAlta (8.2)0.52%—LiquidjsAI8/7/202610/7/2026
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filter at src/filters/array.ts allocated a full clone of its input array via [...toArray(v)] without calling this.context.memoryLimit.use(...), allowing a template render such as {{ huge_array | pop }}…
AplazadaMedia (6.4)0.26%—Seedprod Website BuilderAI8/7/202629/9/2026
El plugin Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'seedprodnestedmenuwidget' del plugin en todas las versiones hasta la 6.20.2, inclusive, debido a una sanitización…
AplazadaMedia (5.4)0.24%—LiquidfilesAI7/7/20269/7/2026
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.
AplazadaMedia (5.4)0.24%—LiquidfilesAI7/7/20269/7/2026
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
AplazadaMedia (5.5)0.47%—Ruijie Rg-uacAI5/7/20266/7/2026
A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Performing a manipulation of the argument upload_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and…
AnalizadaMedia (4.8)0.28%—Redhat Build OF Keycloak5/7/202611/8/2026
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the…
AplazadaBaja (2.1)0.40%—Nextlevelbuilder GoclawAI5/7/20267/7/2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation leads to incorrect authorization. The attack may be launched remotely. The exploit has…
AnalizadaBaja (2.7)0.38%—Redhat Build OF Keycloak3/7/202611/8/2026
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to…
AnalizadaMedia (5.4)0.32%—Redhat Build OF Keycloak3/7/202611/8/2026
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see…
ModificadaMedia (4.9)0.38%—Redhat Build OF Keycloak3/7/202631/8/2026
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of…
AplazadaMedia (4.3)0.49%—Quizandsurveymaster Quiz AND Survey MasterAI3/7/20266/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaAlta (7.3)0.13%—Asus AI Suite 3AI3/7/202617/7/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for…
AplazadaAlta (8.5)0.14%—Asus AI Suite 3AI3/7/202617/7/2026
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on…
AnalizadaAlta (7)0.66%—Juicedata Juicefs2/7/202617/8/2026
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline…
AnalizadaAlta (7.5)0.36%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
AnalizadaAlta (8.8)0.49%—UI Unifi Protect2/7/20266/7/2026
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
AnalizadaAlta (8.1)0.39%—UI Unifi Talk Application2/7/20269/7/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
AnalizadaAlta (8.3)0.37%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
AnalizadaAlta (8.6)0.56%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
En análisisCrítica (9.8)0.41%—UI Unifi Connect2/7/20269/7/2026
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
AnalizadaCrítica (9.9)0.47%—UI Unifi Protect2/7/20267/7/2026
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
AnalizadaAlta (8.8)0.47%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.