Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
21.656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.15% | — | Nilfs UtilitiesAI | 18/6/2026 | 14/7/2026 | NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like… | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Media (6) | 0.24% | — | Shenzhen Liandian Communication Technology V380 IP CameraAI | 18/6/2026 | 22/6/2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data. | |
| Aplazada | Media (6.4) | 0.32% | — | Fancy TestimonialsAI | 18/6/2026 | 18/6/2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.9) | 0.47% | — | Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect… | |
| Analizada | Alta (7.5) | 0.27% | — | Devolutions Unigetui | 17/6/2026 | 24/6/2026 | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a… | |
| Aplazada | Alta (7.5) | 0.50% | — | Joomunited WP Media FolderAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. | |
| Aplazada | Media (5.9) | 0.24% | — | WP Magnific PopupAI | 17/6/2026 | 17/6/2026 | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user. | |
| Aplazada | Alta (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 17/6/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Aplazada | Crítica (9.9) | 0.79% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | LeonieAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Niftypm NiftyAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | FlatonicaAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. | |
| Aplazada | Alta (8.1) | 0.43% | — | WaniumAI | 17/6/2026 | 6/10/2026 | Inclusión local de ficheros no autenticada en versiones de Wanium menor o igual a 1.9.8. | |
| Aplazada | Alta (8.1) | 0.43% | — | IngeniosoAI | 17/6/2026 | 6/10/2026 | Inclusión local de ficheros no autenticada en versiones de Ingenioso menor o igual a 1.14.0. | |
| Aplazada | Alta (8.1) | 0.42% | — | LearnifyAI | 17/6/2026 | 6/10/2026 | Inclusión local de ficheros no autenticada en versiones de Learnify menor o igual a 1.15.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Inisev Social Media AND Share IconsAI | 17/6/2026 | 1/10/2026 | Vulnerabilidad de autorización faltante en Inisev Social Media & Share Icons permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Social Media & Share Icons: desde n/a hasta 2.8.6. | |
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 17/6/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Universal Work Queue | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Universal Work Queue | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Universal Work Queue | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Universal Work Queue | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Process Manufacturing Process Planning | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… |