Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Pendiente de análisisCrítica (9.3)0.62%—Redhat Multicluster Engine FOR KubernetesAI19/8/202629/9/2026
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary…
AplazadaCrítica (9.8)0.86%—Crocoblock JetengineAI19/8/202620/8/2026
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
AplazadaMedia (6.8)0.43%—Crocoblock JetengineAI19/8/202626/8/2026
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored…
AnalizadaAlta (8.1)0.39%—Oracle Agile Engineering Data Management18/8/202624/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data…
AnalizadaAlta (8.8)0.43%—Oracle Agile Engineering Data Management18/8/202624/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data…
AnalizadaAlta (8.1)0.39%—Oracle Applications Platform Engineering18/8/202628/8/2026
Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (component: Valid Session). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Applications…
AnalizadaMedia (6.4)0.15%—Oracle Agile Engineering Data Management18/8/20264/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes…
AnalizadaMedia (4.8)0.22%—Agile Engineering Data Management Product OF Oracle Supply Chain18/8/20264/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile…
AnalizadaAlta (8.2)0.29%—Agile Engineering Data Management Product OF Oracle Supply Chain18/8/20264/9/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile…
ModificadaMedia (6.7)0.18%—Oracle Agile Engineering Data Management18/8/202625/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes…
ModificadaAlta (7)0.13%—Oracle Agile Engineering Data Management18/8/202625/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile…
ModificadaMedia (6.3)0.14%—Oracle Agile Engineering Data Management18/8/202626/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile…
ModificadaAlta (7.5)0.33%—Oracle Agile Engineering Data Management18/8/202625/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached…
AplazadaMedia (5.3)0.64%—Frangoteam FuxaAITdengineAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag…
AplazadaCrítica (9.8)0.56%—Wpmet FundengineAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
AplazadaAlta (7.1)0.41%—Volcengine OpenvikingAI17/8/202624/9/2026
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the…
AplazadaAlta (7.5)0.69%—Wptravelengine WP Travel EngineAI16/8/202620/8/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…
AplazadaMedia (6.5)1.1%—StoreengineAI16/8/202620/8/2026
The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This makes it possible for authenticated attackers, with vendor-level access and above, to…
ModificadaAlta (7.8)0.33%💥 PoCMicrosoft Malware Protection Engine14/8/20263/9/2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.
Pendiente de análisisMedia (5.1)0.18%—Capstone-engine CapstoneAI14/8/202618/9/2026
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K and RISCV backends have missing or…
Pendiente de análisisBaja (2)0.17%—Capstone-engine CapstoneAI14/8/202618/9/2026
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM decoder accumulates the immediate length…
AplazadaMedia (4.3)0.18%—Astro Booking EngineAI14/8/202629/9/2026
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request…
Pendiente de análisisAlta (7.1)0.35%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI13/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable…
Pendiente de análisisAlta (8.8)1.4%—Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.