Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
2649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | |
| Pendiente de análisis | Crítica (9.3) | 0.62% | — | Redhat Multicluster Engine FOR KubernetesAI | 19/8/2026 | 29/9/2026 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary… | |
| Aplazada | Crítica (9.8) | 0.86% | — | Crocoblock JetengineAI | 19/8/2026 | 20/8/2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Crocoblock JetengineAI | 19/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Applications Platform Engineering | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications… | |
| Analizada | Media (6.4) | 0.15% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes… | |
| Analizada | Media (4.8) | 0.22% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Alta (8.2) | 0.29% | — | Agile Engineering Data Management Product OF Oracle Supply Chain | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Modificada | Media (6.7) | 0.18% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes… | |
| Modificada | Alta (7) | 0.13% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile… | |
| Modificada | Media (6.3) | 0.14% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile… | |
| Modificada | Alta (7.5) | 0.33% | — | Oracle Agile Engineering Data Management | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached… | |
| Aplazada | Media (5.3) | 0.64% | — | Frangoteam FuxaAITdengineAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpmet FundengineAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | |
| Aplazada | Alta (7.1) | 0.41% | — | Volcengine OpenvikingAI | 17/8/2026 | 24/9/2026 | OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the… | |
| Aplazada | Alta (7.5) | 0.69% | — | Wptravelengine WP Travel EngineAI | 16/8/2026 | 20/8/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 1.1% | — | StoreengineAI | 16/8/2026 | 20/8/2026 | The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to… | |
| Modificada | Alta (7.8) | 0.33% | 💥 PoC | Microsoft Malware Protection Engine | 14/8/2026 | 3/9/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Capstone-engine CapstoneAI | 14/8/2026 | 18/9/2026 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K and RISCV backends have missing or… | |
| Pendiente de análisis | Baja (2) | 0.17% | — | Capstone-engine CapstoneAI | 14/8/2026 | 18/9/2026 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM decoder accumulates the immediate length… | |
| Aplazada | Media (4.3) | 0.18% | — | Astro Booking EngineAI | 14/8/2026 | 29/9/2026 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 13/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable… | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. |