Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
21.074 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Aplazada | Alta (7.1) | 0.37% | — | Frappe LMSAI | 20/7/2026 | 22/7/2026 | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course. | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Pendiente de análisis | Media (6.5) | 0.39% | 💥 PoC | Opswat Appremover DriverAI | 16/7/2026 | 17/7/2026 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation. | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Aplazada | Alta (7.3) | 0.13% | — | Lenovo Legion ZoneAILenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code. | |
| Analizada | Media (4.3) | 0.36% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty name list the… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase… | |
| Analizada | Crítica (9.8) | 0.98% | — | Spaceapplications Yamcs | 16/7/2026 | 20/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could… | |
| Analizada | Crítica (9.1) | 1.1% | — | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without… | |
| Analizada | Crítica (9.8) | 2.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 17/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform… | |
| Modificada | Media (4.3) | 1.1% | 💥 Exploit | Spaceapplications Yamcs | 16/7/2026 | 18/7/2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no… | |
| Aplazada | Alta (7) | 0.17% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Alta (7) | 0.18% | — | Lenovo APP StoreAI | 16/7/2026 | 16/7/2026 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code. | |
| Aplazada | Media (4.9) | 0.48% | — | Ljapps WP Tripadvisor Review SliderAI | 16/7/2026 | 16/7/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Happy Coders OTP LoginAI | 16/7/2026 | 16/7/2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including administrators, as well as to create new… | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Media (6.1) | 0.38% | — | Webappick Product Feed Manager FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (10) | 0.89% | 💥 PoC | Nocobase Plugin Notification IN APP MessageAI | 15/7/2026 | 20/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal()… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Aplazada | Alta (8.8) | 0.20% | — | Frappe ErpnextAI | 15/7/2026 | 15/7/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope.… | |
| Analizada | Alta (7.8) | 0.17% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Alta (7.8) | 0.23% | — | Adobe Creative Cloud Desktop Application | 14/7/2026 | 28/8/2026 | Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |