Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

14.288 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.3)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux4/8/202631/8/2026
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached…
AnalizadaAlta (7.5)0.87%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
AnalizadaCrítica (9.8)0.95%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
AnalizadaCrítica (10)0.95%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) se ve afectado por una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) que podría provocar una escalada de privilegios. La explotación de este problema no requiere la interacción del usuario. El alcance cambia.
AnalizadaCrítica (10)1.0%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially…
AnalizadaCrítica (9.9)0.97%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) se ve afectado por una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') que podría provocar la ejecución de código arbitrario en el contexto del usuario actual. Un atacante con pocos privilegios podría explotar esta…
AnalizadaCrítica (10)1.4%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does…
AnalizadaCrítica (9.6)0.94%—Adobe Campaign3/8/202628/8/2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.…
Pendiente de análisisAlta (7.1)0.53%—AiohttpAI3/8/202610/9/2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the…
Pendiente de análisisMedia (6.3)0.44%💥 PoCAiohttpAI3/8/202610/9/2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in…
AplazadaCrítica (9.3)0.22%—BaileysAI3/8/202610/9/2026
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The…
AplazadaBaja (1.9)0.21%—Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI3/8/202612/8/2026
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with…
AplazadaMedia (5.5)0.47%—Jina-ai ReaderAI3/8/202612/8/2026
A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote…
AplazadaMedia (5.5)2.7%—Sangfor Operation AND Maintenance Security Management SystemAI3/8/202612/8/2026
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack…
ModificadaMedia (4.4)0.08%—GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202622/9/2026
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or…
ModificadaMedia (4.4)0.14%—GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202622/9/2026
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with…
Pendiente de análisisCrítica (9.3)0.89%💥 PoCCheckpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI3/8/20265/8/2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could…
AnalizadaMedia (5.5)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202631/8/2026
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,…
AnalizadaAlta (8.7)0.20%—Bouncycastle Bc-javaBouncycastle Bcjmail-fipsBouncycastle Bcmail-fipsBouncycastle Bouncy Castle FOR Java LTS3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X…
AplazadaAlta (7.5)0.41%—AI Chatbot FOR WoocommerceAI2/8/202626/8/2026
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to…
AplazadaMedia (6.1)0.36%—WP Responsive Thumbnail SliderAI1/8/202612/8/2026
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']…
AplazadaMedia (6.6)1.2%—Ayecode GetpaidAI1/8/202612/8/2026
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to…
AplazadaMedia (4.9)0.44%—Icegram MailerAI1/8/202612/8/2026
The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()…
AplazadaAlta (7.2)0.42%—Pluginops Mailchimp Subscribe FormAI1/8/202612/8/2026
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaAlta (8.8)0.30%—AI EngineAI1/8/202612/8/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to…