Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.58% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31. | |
| Analizada | Crítica (9.3) | 0.85% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and… | |
| Analizada | Crítica (9.8) | 0.69% | 💥 PoC | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31. | |
| Analizada | Media (5.3) | 0.26% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (6.9) | 0.39% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (5.3) | 0.26% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fixed in version 1.2.31. | |
| Analizada | Baja (2.5) | 0.14% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values. The rrdtool_function_update() function checks metric values with is_numeric() and concatenates them into the RRDtool… | |
| Analizada | Crítica (9.8) | 0.67% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was… | |
| Aplazada | Alta (7.5) | 0.35% | — | Ghost ActivitypubAI | 24/6/2026 | 25/6/2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0. | |
| Analizada | Baja (3.7) | 0.33% | — | Jenkins Active Directory | 24/6/2026 | 26/6/2026 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose… | |
| Aplazada | Media (6.5) | 0.30% | — | Filament ActionsAINextcloud TablesAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and… | |
| Aplazada | Baja (2.1) | 0.35% | — | ActivepiecesAI | 21/6/2026 | 22/6/2026 | A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engine/src/lib/variables/processors/file.ts of the component File URL Handler. The manipulation results in server-side request forgery. The attack can be executed remotely.… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Active Directory | 19/6/2026 | 24/6/2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.7) | 0.08% | — | Steeltoe Configuration AbstractionsAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those… | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Melapress WP Activity LOGAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | |
| Aplazada | Alta (8.1) | 0.35% | — | ItacticsAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in ITactics <= 1.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Booking ActivitiesAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Hedef Media Promotion Interactive Media Marketing INC Related Marketing CloudAI | 12/6/2026 | 17/6/2026 | Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026. | |
| Aplazada | Alta (8.5) | 1.4% | — | KanadojoAIGithub ActionsAI | 11/6/2026 | 14/7/2026 | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the… | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Active IQ Onecollect | 3/6/2026 | 22/7/2026 | Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Active IQ Config Advisor | 3/6/2026 | 22/7/2026 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Analizada | Alta (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Aplazada | Crítica (10) | 0.44% | 💥 PoC | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been… | |
| Aplazada | Crítica (10) | 0.44% | 💥 PoC | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring… |