Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

2202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.40%—Visitor Traffic Real Time Statistics PROAI27/8/202628/8/2026
Inyección SQL no autenticada en Visitor Traffic Real Time Statistics Pro, versiones <= 11.17.
AplazadaCrítica (9.8)0.63%—Soclever Social Login Sharing Buttons With AnalyticsAI22/8/202626/8/2026
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.…
AplazadaAlta (7.5)0.63%—Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI21/8/202626/8/2026
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
AplazadaMedia (5.3)0.35%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI20/8/202624/8/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
Pendiente de análisisMedia (4.3)0.19%—Cisco Secure Malware Analytics APP FOR Splunk SoarAISplunk SoarAI19/8/202620/8/2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user…
AplazadaAlta (7.2)0.65%—Wp-statistics WP StatisticsAI19/8/202620/8/2026
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaAlta (8.8)0.16%—Oracle Product Lifecycle Analytics18/8/202627/8/2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to…
AnalizadaAlta (8.7)0.41%—Oracle Product Lifecycle Analytics18/8/202627/8/2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics.…
AnalizadaAlta (8.5)0.30%—Oracle Product Lifecycle Analytics18/8/202627/8/2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics.…
AnalizadaAlta (7.6)0.32%—Oracle Product Lifecycle Analytics18/8/202610/9/2026
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the cluster, and a size value carried inside the identifier drives an…
AnalizadaMedia (6.5)0.57%—Elasticsearch13/8/20261/9/2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so the validation causes the thread to…
AnalizadaMedia (4.3)0.37%—Elasticsearch13/8/20261/9/2026
A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing…
AnalizadaMedia (6.5)0.57%—Elasticsearch13/8/20261/9/2026
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a self-referential data structure to be created. When a specific…
AnalizadaMedia (6.5)0.47%—Elasticsearch13/8/20261/9/2026
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of…
AnalizadaMedia (6.5)0.47%—Elasticsearch13/8/20261/9/2026
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20264/9/2026
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory,…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure is processed without a depth limit,…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an excessively large memory allocation,…
AnalizadaAlta (8.8)0.60%—Elasticsearch13/8/20261/9/2026
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable index can submit one small search request…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analysis definition that is resolved…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations…
AplazadaCrítica (9.3)1.1%—Fosowl AgenticseekAI13/8/202624/9/2026
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated…