Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

14.298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.2)0.20%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit29/6/202628/9/2026
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.…
AplazadaMedia (6.5)0.33%—Colissimo Officiel Methodes DE Livraison Pour WoocommerceAI29/6/20261/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
AplazadaCrítica (9.9)0.55%—Paid Videochat Turnkey Site PerformerAI29/6/202629/6/2026
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
AplazadaMedia (6.3)0.26%—MainwpAI29/6/202629/6/2026
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
AplazadaBaja (2)0.35%—Codeagstro Complaint Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is…
AnalizadaMedia (5.3)0.17%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux29/6/202631/8/2026
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer…
AplazadaBaja (2.1)0.51%—Coderastro Complaint Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has…
AplazadaMedia (6.8)0.38%—Hitachi Storage NavigatorAIHitachi Virtual Storage PlatformAIHitachi DkcmainAIHitachi SVPAI29/6/202629/9/2026
Vulnerabilidad de exposición de información en Hitachi Storage Navigator. Este problema afecta a Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: antes de DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, antes de DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi…
AplazadaBaja (1.3)0.36%—Aidc-ai Comfyui-copilotAI28/6/202629/6/2026
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed…
AnalizadaBaja (2.3)1.6%💥 ExploitFlowiseai Flowise28/6/20266/7/2026
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can…
AplazadaAlta (8.1)0.38%—Paid Membership PluginAI27/6/202629/6/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active…
AplazadaAlta (8.8)0.20%—Paidmembershipspro Paid Memberships PROAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
AplazadaMedia (4.3)0.14%—Gmail SmtpAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
AplazadaAlta (8.3)0.30%—Mailchimp BlockAI26/6/202626/6/2026
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
AplazadaMedia (5.3)0.29%—Siteground Email MarketingAI26/6/202626/6/2026
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
AnalizadaCrítica (9.8)0.34%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
AnalizadaMedia (5.3)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
AnalizadaAlta (7.5)0.27%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
AnalizadaMedia (5.3)0.24%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
AnalizadaAlta (7.5)0.30%—Jetbrains Youtrack26/6/202627/6/2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
AnalizadaCrítica (9.8)0.33%—Jetbrains Kotlin26/6/202627/6/2026
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
AplazadaAlta (7.1)0.25%—Wedevs WemailAI26/6/202618/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2.
ModificadaAlta (7.5)0.44%—Apache-airflow-providers-ftp26/6/202616/9/2026
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file…