Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

9652 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.43%—Oracle E-business Suite28/5/202621/7/2026
Vulnerabilidad en el producto Oracle Internet Procurement Connector de Oracle E-Business Suite (componente: Operaciones Internas). Las versiones compatibles que están afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP…
AnalizadaAlta (7.4)0.34%—Oracle E-business Suite28/5/202621/7/2026
Vulnerabilidad en el producto Oracle Payments de Oracle E-Business Suite (componente: File Transmission). Las versiones compatibles que están afectadas son 12.2.3-12.2.15. La vulnerabilidad difícil de explotar permite a un atacante no autenticado con acceso a la red a través de HTTPS comprometer Oracle Payments. Los…
AnalizadaCrítica (9.8)0.81%⚠ Explotación activa💥 PoCOracle E-business Suite28/5/202621/7/2026
Vulnerabilidad en el producto Oracle Payments de Oracle E-Business Suite (componente: File Transmission). Las versiones soportadas que están afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso de red vía HTTP comprometer Oracle Payments. Ataques…
AplazadaMedia (5)0.41%—Learningcircuit Local Deep ResearchAI28/5/202617/6/2026
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The main logic is to…
AplazadaMedia (5)0.36%—Learningcircuit Local Deep ResearchAI28/5/202617/6/2026
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an…
AnalizadaAlta (8.2)0.50%—Jg-rp Python Liquid28/5/202617/6/2026
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template authors to load and render arbitrary files…
AplazadaAlta (7.5)0.48%—EsbuildAIEsm.shAI28/5/202617/6/2026
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return arbitrary files from the…
ModificadaMedia (5.3)0.72%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing…
ModificadaMedia (6.8)0.52%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful…
ModificadaMedia (4.9)0.90%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response…
ModificadaMedia (4.3)0.49%—Redhat Build OF Keycloak28/5/202620/8/2026
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection.…
ModificadaMedia (6.5)0.38%—Redhat Build OF Keycloak28/5/202615/9/2026
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them…
ModificadaAlta (7.3)0.49%—Redhat Build OF Keycloak28/5/202615/7/2026
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the…
ModificadaMedia (5.3)0.57%💥 PoCRedhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker…
ModificadaAlta (7.5)0.26%—Redhat Build OF Keycloak28/5/202620/8/2026
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of…
ModificadaMedia (6.5)0.46%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an…
ModificadaMedia (4.3)0.37%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after…
AnalizadaMedia (5.5)0.29%—Jenkins Buildgraph-view27/5/202617/6/2026
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
ModificadaAlta (8.8)0.59%—Redhat Build OF Keycloak27/5/202626/6/2026
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This…
ModificadaMedia (4.2)0.43%—Redhat Build OF Keycloak27/5/202620/8/2026
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the…
AplazadaCrítica (9.9)0.55%—Ludwig YOU QuickwebpAI27/5/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly:…
AplazadaMedia (6.5)0.22%—Liquidweb WpcompleteAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.
AplazadaCrítica (9.3)0.40%—Whitestudio Easy Form BuilderAI27/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6.
AplazadaMedia (6.4)0.30%—Livemesh Addons FOR Beaver BuilderAI27/5/202617/6/2026
The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user…
AplazadaMedia (6.4)0.30%—Livemesh Wpbakery Page Builder AddonsAI27/5/202617/6/2026
The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check…