Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
14.298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.2) | 0.20% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit | 29/6/2026 | 28/9/2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.… | |
| Aplazada | Media (6.5) | 0.33% | — | Colissimo Officiel Methodes DE Livraison Pour WoocommerceAI | 29/6/2026 | 1/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Paid Videochat Turnkey Site PerformerAI | 29/6/2026 | 29/6/2026 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | MainwpAI | 29/6/2026 | 29/6/2026 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | |
| Aplazada | Baja (2) | 0.35% | — | Codeagstro Complaint Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is… | |
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Aplazada | Baja (2.1) | 0.51% | — | Coderastro Complaint Management SystemAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has… | |
| Aplazada | Media (6.8) | 0.38% | — | Hitachi Storage NavigatorAIHitachi Virtual Storage PlatformAIHitachi DkcmainAIHitachi SVPAI | 29/6/2026 | 29/9/2026 | Vulnerabilidad de exposición de información en Hitachi Storage Navigator. Este problema afecta a Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: antes de DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, antes de DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi… | |
| Aplazada | Baja (1.3) | 0.36% | — | Aidc-ai Comfyui-copilotAI | 28/6/2026 | 29/6/2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed… | |
| Analizada | Baja (2.3) | 1.6% | 💥 Exploit | Flowiseai Flowise | 28/6/2026 | 6/7/2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can… | |
| Aplazada | Alta (8.1) | 0.38% | — | Paid Membership PluginAI | 27/6/2026 | 29/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active… | |
| Aplazada | Alta (8.8) | 0.20% | — | Paidmembershipspro Paid Memberships PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. | |
| Aplazada | Media (4.3) | 0.14% | — | Gmail SmtpAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Alta (8.3) | 0.30% | — | Mailchimp BlockAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Siteground Email MarketingAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | |
| Analizada | Crítica (9.8) | 0.34% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | |
| Analizada | Media (5.3) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | |
| Analizada | Alta (7.5) | 0.27% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | |
| Analizada | Media (5.3) | 0.24% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | |
| Analizada | Alta (7.5) | 0.30% | — | Jetbrains Youtrack | 26/6/2026 | 27/6/2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | |
| Analizada | Crítica (9.8) | 0.33% | — | Jetbrains Kotlin | 26/6/2026 | 27/6/2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs WemailAI | 26/6/2026 | 18/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2. | |
| Modificada | Alta (7.5) | 0.44% | — | Apache-airflow-providers-ftp | 26/6/2026 | 16/9/2026 | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file… |