Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
2624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | User Access ManagerAI | 5/8/2026 | 12/8/2026 | The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and… | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Aplazada | Alta (7.5) | 1.0% | — | User Access ManagerAI | 2/8/2026 | 12/8/2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Aplazada | Media (5.3) | 0.45% | — | GoaccessAI | 30/7/2026 | 8/9/2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed… | |
| Aplazada | Alta (8.7) | 0.47% | — | GoaccessAI | 30/7/2026 | 8/9/2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing… | |
| Aplazada | Alta (7.1) | 0.45% | — | GoaccessAI | 30/7/2026 | 8/9/2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Verify Identity AccessIBM Verify Identity Access Container | 30/7/2026 | 12/8/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error… | |
| Analizada | Media (6.1) | 0.27% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 29/9/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 1/10/2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | |
| Aplazada | Media (6.1) | 0.27% | — | WP Real IP Based Access ControlAI | 30/7/2026 | 30/7/2026 | The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any… | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.24% | — | Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (4.3) | 0.14% | — | WP Accessibility HelperAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Equalize Digital Accessibility CheckerAI | 23/7/2026 | 23/7/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (8) | 0.36% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Access Manager | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Access Manager | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Media (5.3) | 0.32% | — | Oracle Access Manager | 21/7/2026 | 27/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Access Manager | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While… |