Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.55%—CactiAI5/8/202626/8/2026
Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified.
Pendiente de análisisCrítica (9.5)2.1%💥 ExploitRails Action PackAILibvipsAIRubyonrails Active StorageAI30/7/202610/9/2026
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured…
AplazadaCrítica (9.3)0.41%—ActivepiecesAI30/7/202630/7/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing embedded data and allowing modified code to…
Pendiente de análisisAlta (8.8)0.80%—Samba Active Directory Domain ControllerAI30/7/202630/7/2026
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted…
AnalizadaMedia (6.5)0.46%—Apache ActivemqApache Activemq ALLApache Activemq Broker28/7/20265/8/2026
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows…
AnalizadaAlta (7.5)0.78%—Apache ActivemqApache Activemq ALLApache Activemq Amqp28/7/20265/8/2026
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead…
AplazadaAlta (7.3)0.34%—Eventeon Action UserAI24/7/202624/7/2026
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities…
AplazadaAlta (8.5)0.48%—Github ActionsAICal.comAI23/7/20261/10/2026
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a…
AplazadaMedia (5.4)0.14%—Melapress WP Activity LOGAIMelapress WP Activity LOG PremiumAI23/7/20265/8/2026
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
AnalizadaMedia (4.1)0.23%—Oracle Interaction Blending21/7/202631/7/2026
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending.…
AnalizadaAlta (7.2)0.49%—Oracle Interaction Blending21/7/202631/7/2026
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Interaction Blending.…
AnalizadaMedia (5.4)0.23%—Oracle Customer Interaction History21/7/202619/8/2026
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction…
AnalizadaAlta (7.1)0.16%—Oracle Interaction Blending21/7/20267/8/2026
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to…
AnalizadaCrítica (9.1)0.41%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to…
AnalizadaMedia (6.1)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute…
AnalizadaMedia (5.4)0.24%—Bestpractical Request Tracker20/7/202618/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include…
AnalizadaMedia (5.4)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject…
AnalizadaMedia (6.1)0.26%—Bestpractical Request Tracker20/7/20267/8/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session.…
AplazadaMedia (5.3)0.24%—ActivepiecesAI16/7/202618/7/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a missing null-check on the decoded fileId, this allowed any caller holding…
AplazadaMedia (5.9)0.84%—ActivepiecesAI16/7/202617/7/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a temporary directory on the server and then writes flow, table, and connection state into it before pushing back, and two separate weaknesses allowed those writes to…
Pendiente de análisisMedia (5.3)0.77%—Anthropic Claude Code ActionAI16/7/202618/7/2026
Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-controlled pull request head branches, read .mcp.json from the working directory via default setting sources, and unconditionally enabled all project…
AplazadaAlta (8.8)0.46%—Github ActionsAIMaaassistantarknightsAI15/7/202612/8/2026
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork…
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.7%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)1.2%—Ivanti Xtraction14/7/20266/8/2026
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.