Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.28% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise… | |
| Pendiente de análisis | Media (6.8) | 0.31% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Oracle Java SEAIOracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAI | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM… | |
| Aplazada | Media (6) | 0.38% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |
| Aplazada | Alta (8.5) | 0.53% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |
| Aplazada | Media (5.1) | 0.31% | — | Saurus CMS Community EditionAI | 13/8/2026 | 31/8/2026 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can… | |
| Analizada | Media (5.5) | 0.12% | — | Foxit PDF EditorFoxit PDF Reader | 13/8/2026 | 10/9/2026 | Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures. | |
| Aplazada | Media (6.3) | 0.17% | — | Ministry OF Justice Uyap Document EditorAI | 12/8/2026 | 26/8/2026 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 17/8/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 2.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | |
| Modificada | Alta (8) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 2/9/2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.4) | 0.17% | — | Line FOR WindowsAIMicrosoft MsfteditAI | 10/8/2026 | 28/8/2026 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpide File Manager AND Code EditorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | |
| Aplazada | Media (4.3) | 0.19% | — | Themeeditor Theme EditorAI | 1/8/2026 | 29/9/2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can… | |
| Aplazada | Media (5.3) | 0.53% | — | Xdsoft Jodit EditorAI | 31/7/2026 | 9/9/2026 | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This… | |
| Aplazada | Media (5.4) | 0.31% | — | Xdsoft Jodit EditorAI | 31/7/2026 | 9/9/2026 | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass… | |
| Aplazada | Crítica (9.8) | 0.79% | — | PheditorAI | 27/7/2026 | 27/7/2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials… | |
| Aplazada | Alta (8.8) | 0.67% | — | PheditorAI | 27/7/2026 | 28/7/2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). After the fix for GHSA-9643-6xjp-vx57 (which added $ to the… | |
| Aplazada | Alta (8.8) | 0.73% | — | PheditorAI | 27/7/2026 | 27/7/2026 | Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to… | |
| Aplazada | Crítica (9.9) | 7.5% | — | PheditorAI | 27/7/2026 | 27/7/2026 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely… | |
| Aplazada | Media (5.9) | 0.24% | — | Checkout Field EditorAI | 27/7/2026 | 27/7/2026 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. |