Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Casap Automated Enrollment SystemAI | 29/7/2026 | 1/10/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. | |
| Analizada | Media (5.5) | 0.25% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.5) | 0.73% | — | Uncannyowl Uncanny AutomatorAI | 28/7/2026 | 28/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and… | |
| Aplazada | Alta (7.6) | 0.38% | — | Uncannyowl Uncanny AutomatorAI | 23/7/2026 | 23/7/2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Autopay DLA WoocommerceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. | |
| Analizada | Media (6.3) | 0.14% | — | Oracle Autonomous Health Framework | 21/7/2026 | 6/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to… | |
| Aplazada | Alta (8.1) | 1.0% | — | Uncannyowl Uncanny AutomatorAI | 16/7/2026 | 17/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Baja (2.1) | 0.45% | — | Zhinianboke Xianyu-auto-replyAI | 14/7/2026 | 15/7/2026 | A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched… | |
| Aplazada | Media (5.5) | 0.50% | — | Zhinianboke Xianyu-auto-replyAI | 14/7/2026 | 15/7/2026 | A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has… | |
| Pendiente de análisis | Alta (8.4) | 0.53% | — | Rockwellautomation Factorytalk Datamosaix Private CloudAI | 14/7/2026 | 14/7/2026 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on… | |
| Analizada | Alta (7.3) | 0.17% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to… | |
| Analizada | Alta (7.3) | 0.15% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a… | |
| Analizada | Media (5.4) | 0.18% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the… | |
| Pendiente de análisis | Alta (7.2) | 0.44% | — | Rockwellautomation ThinmanagerAI | 14/7/2026 | 14/7/2026 | A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. | |
| Pendiente de análisis | Alta (8.7) | 0.23% | — | Allen Bradley 1756-en2AIAllen Bradley 1756-en3AIRockwellautomation 1756-enbtAI | 14/7/2026 | 14/7/2026 | A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover… | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Pendiente de análisis | Crítica (10) | 0.41% | — | Rockwellautomation 1715-aentrAI | 14/7/2026 | 14/7/2026 | A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete… | |
| Aplazada | Media (4.9) | 0.19% | — | Themeisle Auto Featured ImageAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4. |