Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.56% | — | Minio | 8/4/2026 | 24/7/2026 | MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader's nextSplit() function calls… | |
| Analizada | Alta (7.1) | 0.21% | — | Minio | 31/3/2026 | 24/7/2026 | MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal… | |
| Aplazada | Media (5.4) | 0.18% | — | Dogblocker Minify HtmlAI | 31/3/2026 | 25/7/2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged… | |
| Analizada | Media (6.1) | 0.25% | — | Miniorange Saml SSO - Service Provider | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3. | |
| En análisis | Media (4.3) | 0.18% | — | Hitachi OPS Center Administrator | 25/3/2026 | 12/8/2026 | Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8. | |
| Pendiente de análisis | Alta (8.7) | 0.38% | — | Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI | 24/3/2026 | 17/6/2026 | Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour. | |
| Analizada | Crítica (9.1) | 0.54% | — | Minio | 24/3/2026 | 17/6/2026 | MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration,… | |
| Analizada | Crítica (9.2) | 0.61% | — | Minio | 24/3/2026 | 17/6/2026 | MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials… | |
| Aplazada | Alta (8.6) | 0.15% | — | MiniftpAI | 22/3/2026 | 17/6/2026 | MiniFtp contains a buffer overflow vulnerability in the parseconf_load_setting function that allows local attackers to execute arbitrary code by supplying oversized configuration values. Attackers can craft a miniftpd.conf file with values exceeding 128 bytes to overflow stack buffers and overwrite the return address,… | |
| Aplazada | Media (5.3) | 0.44% | — | Rest API TO MiniprogramAI | 21/3/2026 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing… | |
| Aplazada | Media (4.3) | 0.18% | — | Lobot Slider AdministratorAI | 21/3/2026 | 17/6/2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fourty_slider_options_page function. This makes it possible for unauthenticated attackers to modify plugin slider-page… | |
| Aplazada | Media (4.3) | 0.14% | — | SR WP Minify HtmlAI | 21/3/2026 | 17/6/2026 | The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing nonce validation on the sr_minify_html_theme() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted… | |
| Modificada | Media (5.1) | 0.18% | — | Mackron Miniaudio | 17/3/2026 | 14/7/2026 | miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding… | |
| Aplazada | Media (5.3) | 0.29% | — | Raratheme THE MinimalAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme The Minimal the-minimal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Minimal: from n/a through <= 1.2.9. | |
| Analizada | Alta (7.5) | 0.60% | — | DJI Mavic Mini FirmwareDJI Spark FirmwareDJI Mini SE Firmware | 4/3/2026 | 17/6/2026 | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem | |
| Analizada | Crítica (9.8) | 3.0% | — | Mobvoi Tichome Mini Firmware | 4/3/2026 | 17/6/2026 | A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI | 3/3/2026 | 17/6/2026 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators. | |
| Analizada | Alta (7.5) | 0.51% | — | Minimatch Project Minimatch | 26/2/2026 | 17/6/2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking… | |
| Analizada | Alta (7.5) | 0.60% | — | Minimatch Project Minimatch | 26/2/2026 | 17/6/2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and… | |
| Analizada | Alta (8.7) | 0.53% | — | Minimatch Project Minimatch | 20/2/2026 | 17/6/2026 | minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test… | |
| Analizada | Baja (1.9) | 0.21% | — | Minisat | 18/2/2026 | 17/6/2026 | A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs to be launched… | |
| Analizada | Media (6.9) | 0.79% | — | Rybber Minigal Nano | 11/2/2026 | 14/7/2026 | MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to prevent traversal by removing dot-dot sequences, but this protection can be bypassed using crafted directory patterns.… | |
| Analizada | Media (5.1) | 0.41% | — | Rybber Minigal Nano | 11/2/2026 | 14/7/2026 | MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is… | |
| Aplazada | Media (5.3) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 6/2/2026 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' option parameter. This… | |
| Analizada | Alta (8.7) | 0.80% | — | Edimax Ew-7438rpn Mini Firmware | 5/2/2026 | 17/6/2026 | Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication. |