Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

21.656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.39%—Oceanicsoft ValeappAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaCrítica (9.8)1.1%—Creativethemes Blocksy CompanionAI9/7/20269/7/2026
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring…
Pendiente de análisisBaja (3.8)0.27%—Vmware PinnipedAI9/7/20269/7/2026
A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the…
AplazadaCrítica (9.8)1.1%—Miniorange OTP Login Verification AND SMS NotificationsAI9/7/20269/7/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the…
AnalizadaMedia (4.9)0.39%—Snipeitapp Snipe-it8/7/202610/7/2026
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API…
AnalizadaBaja (1.3)0.28%—Snipeitapp Snipe-it8/7/202610/7/2026
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the…
AplazadaMedia (6.8)0.28%—Code 27 Companion HUBAI8/7/20269/7/2026
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset
AplazadaMedia (6.8)0.28%💥 PoCCode27 Companion HUBAIGoogle Android Debug BridgeAI8/7/202610/7/2026
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components
AplazadaCrítica (9.2)3.6%💥 ExploitBlocksy Companion PROAI8/7/20268/7/2026
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom…
AnalizadaAlta (7.8)0.18%—Omnissa Workspace ONE Tunnel8/7/202610/7/2026
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
AnalizadaAlta (7.5)0.46%—Tanium Server8/7/202610/7/2026
Tanium addressed a denial of service vulnerability in Tanium Server.
AplazadaBaja (2.1)0.29%—Flask-dashboard Flask-monitoringdashboardAI8/7/20268/7/2026
A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was…
ModificadaMedia (6.3)0.80%—Phoenixframework Phoenix7/7/202624/9/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program…
ModificadaAlta (8.7)0.78%—Phoenixframework Phoenix7/7/202624/9/2026
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll). This vulnerability is…
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+756/7/20267/7/2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1056/7/20267/7/2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
AnalizadaAlta (8.6)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/7/20269/7/2026
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful…
Pendiente de análisisMedia (4.8)0.31%—Uniflow Universal Login ManagerAI6/7/20266/7/2026
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Exploitation requires administrative privileges and may disclose configuration data…
AnalizadaMedia (6.1)0.25%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/7/20266/10/2026
El software acepta entrada proporcionada por el usuario a través de un parámetro de URL sin una codificación de salida adecuada antes de reflejarla de vuelta al navegador del usuario. Esta condición permite a un atacante inyectar contenido de script malicioso en páginas servidas por la aplicación. Al aprovechar esta…
AplazadaCrítica (9.1)1.4%—FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI6/7/20266/7/2026
El plugin FileOrganizer para WordPress anterior a la versión 1.1.9, el plugin Advanced File Manager para WordPress anterior a la versión 5.4.12, el plugin File Manager Pro para WordPress anterior a la versión 2.1.1 y el plugin File Manager para WordPress anterior a la versión 8.0.4 no escapan correctamente un…
AplazadaAlta (8.8)0.73%—FileorganizerAI6/7/20266/7/2026
El plugin de WordPress FileOrganizer, en versiones anteriores a la 1.2.0, no valida el tipo de archivo en varias de sus operaciones de gestión de archivos, lo que permite a los usuarios autenticados a los que se les ha concedido acceso al gestor de archivos —que, gracias a su complemento premium, puede ampliarse a los…
AplazadaMedia (5.5)0.50%—Sourcecodester Online Examination AND Learning Management SystemAI6/7/20266/7/2026
A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack…
AplazadaBaja (2.1)0.37%—Sourcecodester Online Examination & Learning Management SystemAI6/7/20266/7/2026
A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to…