Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.69% | — | Apache Polaris | 4/5/2026 | 17/6/2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is treated as a wildcard… | |
| Analizada | Crítica (9.4) | 0.58% | — | Apache Polaris | 4/5/2026 | 17/6/2026 | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker-… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Solaris | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in… | |
| Aplazada | Media (4.1) | 0.23% | — | Parisneo LollmsAI | 8/4/2026 | 25/7/2026 | An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of… | |
| Analizada | Media (5.4) | 0.30% | — | Farisc0de Uploady | 26/3/2026 | 17/6/2026 | Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename containing JavaScript code, which is… | |
| Aplazada | Baja (2.1) | 0.47% | — | Jcharis Machine-learning-web-appsAIPocoo Jinja2AI | 11/3/2026 | 17/6/2026 | A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such… | |
| Aplazada | Alta (8.8) | 0.21% | — | Alive ParishAI | 6/3/2026 | 17/6/2026 | Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the images/uploaded… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Themerex SolarisAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5. | |
| Analizada | Media (6.1) | 0.22% | — | Claris Filemaker Server | 24/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7. | |
| Aplazada | Alta (7.1) | 0.18% | — | Parisholley Asynchronous JavascriptAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paris Holley Asynchronous Javascript asynchronous-javascript allows Reflected XSS.This issue affects Asynchronous Javascript: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.4) | 0.11% | — | Themes4wp Popularis ExtraAI | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Popularis Extra: from n/a through <= 1.2.10. | |
| Aplazada | Crítica (9.6) | 0.90% | — | Parisneo Lollms-webuiAI | 2/2/2026 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicious `name` parameter, leading to the… | |
| Aplazada | Alta (8.2) | 0.59% | — | Parisneo LollmsAI | 2/2/2026 | 17/6/2026 | A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cancel_generation`, `generate_msg`, and `generate_msg_from` without implementing… | |
| Analizada | Media (5) | 0.14% | — | Oracle Solaris | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks… | |
| Analizada | Media (5.8) | 0.22% | — | Oracle Solaris | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human… | |
| Modificada | Media (5.3) | 0.33% | — | Oracle Solaris | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized… | |
| Analizada | Media (5.8) | 0.22% | — | Oracle Solaris | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human… | |
| Analizada | Media (6.8) | 0.30% | 💥 PoC | Softwareag Aris | 7/1/2026 | 17/6/2026 | A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware | |
| Analizada | Media (6.5) | 0.36% | 💥 PoC | Softwareag Aris | 7/1/2026 | 17/6/2026 | In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit this behavior to rapidly upload a large volume of files, potentially leading to resource exhaustion such as disk space… | |
| Aplazada | Media (5.3) | 0.19% | — | Arista EOSAI | 6/1/2026 | 7/10/2026 | On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic. | |
| Aplazada | Alta (7.1) | 0.30% | — | Arista EOSAI | 16/12/2025 | 17/6/2026 | On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue was discovered internally by Arista and… | |
| Analizada | Media (5.4) | 0.17% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4. | |
| Analizada | Crítica (9.8) | 1.0% | 💥 PoC | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve… | |
| Analizada | Media (5.3) | 0.23% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully… |