Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)3.1%—Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
AplazadaMedia (5.4)0.14%—ShopengineAI13/8/202626/8/2026
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and…
Pendiente de análisisMedia (5.8)0.40%—Redhat Multicluster EngineAI12/8/202629/9/2026
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept…
Pendiente de análisisCrítica (9.9)0.88%—Redhat Multicluster EngineAIRedhat Cluster Curator ControllerAI12/8/202629/9/2026
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the…
AplazadaMedia (5.3)0.32%—Wptravelengine WP Travel EngineAI12/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information,…
AplazadaAlta (8.7)0.55%—Phoenixcontact Plcnext EngineerAI12/8/202629/9/2026
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.
Pendiente de análisisCrítica (9.8)3.3%—Manageengine DDI CentralAI11/8/202631/8/2026
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
AplazadaAlta (7.5)0.49%—Python-engineioAI11/8/202618/9/2026
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to…
AplazadaAlta (7.5)0.57%—Python-engineioAI11/8/202618/9/2026
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when…
Pendiente de análisisCrítica (10)0.81%—3DS Simulia Execution EngineAI11/8/202628/8/2026
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Pendiente de análisisAlta (8.5)1.8%—Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI11/8/202631/8/2026
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
AplazadaMedia (6.1)0.27%—Crocoblock JetengineAI10/8/202626/8/2026
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored…
AplazadaMedia (5.1)3.9%—Kirachon Context-engineAI8/8/202612/8/2026
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue.…
AplazadaMedia (5)0.34%—AI EngineAI8/8/202626/8/2026
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level…
AplazadaMedia (4.8)0.27%—AI EngineAI8/8/202626/8/2026
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's…
AplazadaMedia (5.3)0.16%—Wptravelengine WP Travel EngineAI6/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using…
AplazadaAlta (7.1)0.25%—AI EngineAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
AplazadaMedia (6.5)0.43%—AI EngineAI6/8/202626/8/2026
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to…
AplazadaAlta (8.8)0.52%—Magistrala Rules EngineAI5/8/202626/8/2026
Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client…
Pendiente de análisisCrítica (9.1)0.64%—Multicluster Engine FOR Kubernetes ClustercuratorAI5/8/20268/9/2026
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a…
AplazadaMedia (5.4)0.23%—Crocoblock JetengineAI2/8/202626/8/2026
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.
AplazadaAlta (8.6)0.92%💥 PoCArcadedb-engineAI1/8/20268/9/2026
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes…
AplazadaAlta (8.8)0.30%—AI EngineAI1/8/202612/8/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (6.1)0.27%—IBM Engineering Requirements Management Doors WEB Access30/7/202629/9/2026
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…