Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
21.664 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.52% | — | Infiniflow RagflowAI | 29/5/2026 | 21/7/2026 | RAGFlow es un motor RAG (Generación Aumentada por Recuperación) de código abierto. En la versión 0.24.0 y anteriores, una inyección de plantilla Jinja2 en el generador de prompts (rag/prompts/generator.py) permite a cualquier usuario autenticado ejecutar comandos arbitrarios del sistema operativo en el servidor.… | |
| Aplazada | Alta (8.8) | 0.38% | — | Wprepeat WOO Infinite Scroll AND Ajax PaginationAI | 29/5/2026 | 21/7/2026 | El plugin WooCommerce Infinite Scroll and Ajax Pagination para WordPress es vulnerable a la inyección de objetos PHP en todas las versiones hasta la 1.8, inclusive, a través del parámetro 'settings' en la función 'import_settings'. Esto se debe a la deserialización de datos no confiables suministrados a través de la… | |
| Aplazada | Media (4.4) | 0.36% | — | Postsnippets Post SnippetsAI | 29/5/2026 | 21/7/2026 | El plugin Post Snippets para WordPress es vulnerable a cross-site scripting almacenado en todas las versiones hasta la 4.0.19, inclusive. Esto se debe a un escape de salida insuficiente del contenido de fragmentos importados al renderizar variables de JavaScript en el editor de entradas. Específicamente, el método… | |
| Analizada | Alta (7.4) | 0.34% | — | Miniorange Saml SSO - Service Provider | 28/5/2026 | 21/7/2026 | La vulnerabilidad de 'Improper Check for Unusual or Exceptional Conditions' en Drupal SAML SSO - Service Provider permite la escalada de privilegios. Este problema afecta a SAML SSO - Service Provider: desde la versión 0.0.0 anterior a la 3.1.4. | |
| Aplazada | Alta (8.2) | 0.60% | — | Usagi-org Ai-goofish-monitorAI | 28/5/2026 | 21/7/2026 | Usagi-org ai-goofish-monitor contiene una vulnerabilidad de lectura arbitraria de archivos no autenticada en el endpoint GET /API/prompts/{filename} en implementaciones de Windows que permite a atacantes remotos no autenticados leer archivos arbitrarios suministrando rutas absolutas de Windows o secuencias de salto… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Universal Work Queue | 28/5/2026 | 21/7/2026 | Vulnerabilidad en el producto Oracle Universal Work Queue de Oracle E-Business Suite (componente: Work Provider Site Level Administration). Las versiones compatibles que están afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante con pocos privilegios y acceso a la red a través… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic. | |
| Analizada | Media (5.5) | 0.10% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock. | |
| Analizada | Alta (7.8) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the… | |
| Analizada | Media (5.5) | 0.15% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects. | |
| Analizada | Alta (7.8) | 0.17% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses. | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses. | |
| Analizada | Media (6.1) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to… | |
| Analizada | Baja (3.3) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops. | |
| Analizada | Media (5.5) | 0.13% | — | Canonical Ubuntu Linux | 28/5/2026 | 17/6/2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion. | |
| Aplazada | Media (5) | 0.41% | — | Learningcircuit Local Deep ResearchAI | 28/5/2026 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The main logic is to… | |
| Aplazada | Media (5) | 0.36% | — | Learningcircuit Local Deep ResearchAI | 28/5/2026 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an… | |
| Analizada | Alta (8.4) | 0.45% | — | Canonical Multipass | 28/5/2026 | 17/6/2026 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain… | |
| Analizada | Alta (7.8) | 0.16% | — | Canonical Multipass | 28/5/2026 | 17/6/2026 | An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and… | |
| Analizada | Alta (8.5) | 0.53% | — | Apache Ignite | 28/5/2026 | 7/10/2026 | Vulnerabilidad de salto de ruta relativo en la API REST de Apache Ignite. Los usuarios autenticados de la API REST pueden leer cualquier archivo en el servidor con el comando 'cmd=log' y una ruta de registro elaborada de cierta manera. Este problema afecta a Apache Ignite: desde la 2.0.0 hasta la 2.17.0. Se recomienda… | |
| Aplazada | Alta (8.5) | 0.15% | 💥 PoC | Acer NitrosenseAI | 28/5/2026 | 17/6/2026 | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the… | |
| Analizada | Alta (8.8) | 0.65% | — | Tanium Connect | 27/5/2026 | 17/6/2026 | Tanium addressed an unauthorized code execution vulnerability in Connect. |