Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Shobdullar ShopengineAI | 15/9/2026 | 15/9/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and including, 4.9.5 due to insufficient input… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Flowable-engineAI | 14/9/2026 | 24/9/2026 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external… | |
| Aplazada | Alta (8.8) | 0.31% | — | Extremenetworks IQ EngineAI | 14/9/2026 | 22/9/2026 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Baja (3.7) | 0.19% | — | Wptravelengine WP TravelAI | 9/9/2026 | 9/9/2026 | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| Pendiente de análisis | Media (5) | 0.29% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| Pendiente de análisis | Media (5.7) | 0.35% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 28/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |
| Analizada | Media (6.5) | 0.32% | — | Wolfssl Wolfengine | 28/8/2026 | 29/9/2026 | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant… | |
| Analizada | Alta (7.4) | 0.38% | — | Wolfssl Wolfengine | 28/8/2026 | 29/9/2026 | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream… | |
| Aplazada | Alta (8.5) | 0.36% | — | Woocart Suggestion Engine FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | AI EngineAI | 26/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account. | |
| Aplazada | Alta (7.7) | 0.44% | — | AI EngineAI | 26/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host.… | |
| Aplazada | Alta (7.2) | 0.58% | — | ShopengineAI | 25/8/2026 | 28/9/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the WordPress core `import_start` action hook with no… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpmet FundengineAI | 25/8/2026 | 26/8/2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.37% | — | Wpmet FundengineAI | 25/8/2026 | 26/8/2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.25% | — | Brave Conversion EngineAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | |
| Aplazada | Alta (8.3) | 0.34% | — | Volcengine OpenvikingAI | 21/8/2026 | 24/9/2026 | OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD… | |
| Aplazada | Alta (7.2) | 0.46% | — | AI EngineAI | 21/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network… | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 21/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's… | |
| Aplazada | Media (6.8) | 0.19% | — | Capstone-engine CapstoneAI | 20/8/2026 | 18/9/2026 | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A… | |
| Aplazada | Alta (7.3) | 0.19% | — | Capstone-engine CapstoneAI | 20/8/2026 | 18/9/2026 | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpmet FundengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |