Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.26%—Shobdullar ShopengineAI15/9/202615/9/2026
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input…
Pendiente de análisisAlta (7.1)0.46%—Flowable-engineAI14/9/202624/9/2026
Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external…
AplazadaAlta (8.8)0.31%—Extremenetworks IQ EngineAI14/9/202622/9/2026
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
Pendiente de análisisAlta (8.7)0.27%—Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI11/9/202611/9/2026
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users…
AplazadaBaja (3.7)0.19%—Wptravelengine WP TravelAI9/9/20269/9/2026
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.
Pendiente de análisisMedia (6.3)0.38%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Pendiente de análisisMedia (5)0.29%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Pendiente de análisisMedia (6.3)0.38%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Pendiente de análisisMedia (5.7)0.35%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI28/8/202628/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
AnalizadaMedia (6.5)0.32%—Wolfssl Wolfengine28/8/202629/9/2026
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant…
AnalizadaAlta (7.4)0.38%—Wolfssl Wolfengine28/8/202629/9/2026
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream…
AplazadaAlta (8.5)0.36%—Woocart Suggestion Engine FOR WoocommerceAI27/8/202628/8/2026
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
AplazadaMedia (5.3)0.30%—AI EngineAI26/8/202626/8/2026
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
AplazadaAlta (7.7)0.44%—AI EngineAI26/8/202626/8/2026
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host.…
AplazadaAlta (7.2)0.58%—ShopengineAI25/8/202628/9/2026
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no…
AplazadaMedia (6.4)0.35%—Wpmet FundengineAI25/8/202626/8/2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.37%—Wpmet FundengineAI25/8/202626/8/2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.25%—Brave Conversion EngineAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
AplazadaAlta (8.3)0.34%—Volcengine OpenvikingAI21/8/202624/9/2026
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD…
AplazadaAlta (7.2)0.46%—AI EngineAI21/8/202626/8/2026
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network…
Pendiente de análisisAlta (7.7)0.63%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI21/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's…
AplazadaMedia (6.8)0.19%—Capstone-engine CapstoneAI20/8/202618/9/2026
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A…
AplazadaAlta (7.3)0.19%—Capstone-engine CapstoneAI20/8/202618/9/2026
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through…
AplazadaCrítica (9.8)0.56%—Wpmet FundengineAI20/8/202620/8/2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.