Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3977 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.92% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (5.3) | 0.36% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. | |
| Analizada | Media (5.3) | 0.46% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address. | |
| Aplazada | Alta (7.1) | 0.25% | — | Zaytech Smart Online Order FOR CloverAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| Aplazada | Media (6.6) | 0.51% | — | Baseline-browser-mappingAI | 13/8/2026 | 9/9/2026 | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. | |
| Pendiente de análisis | Media (6.3) | 1.1% | — | GMS Command-line InterfaceAI | 11/8/2026 | 28/8/2026 | An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. | |
| Aplazada | Alta (8.7) | 0.51% | — | Inventec Appliances Chiline CloudAI | 11/8/2026 | 26/8/2026 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data. | |
| Pendiente de análisis | Alta (7.6) | 0.51% | — | Data Science PipelinesAIArgoproj Argo WorkflowsAI | 10/8/2026 | 8/9/2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.… | |
| Pendiente de análisis | Alta (7.1) | 0.48% | — | Kubeflow Data Science PipelinesAI | 10/8/2026 | 21/9/2026 | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to… | |
| Pendiente de análisis | Alta (8.8) | 0.73% | — | Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | Kubeflow Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be… | |
| Aplazada | Alta (8.4) | 0.17% | — | Line FOR WindowsAIMicrosoft MsfteditAI | 10/8/2026 | 28/8/2026 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. | |
| Aplazada | Media (5.5) | 0.56% | — | Sourcecodester Online Clothing StoreAIAdobe DreamweaverAI | 7/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit… | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Sharepoint Online | 7/8/2026 | 7/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.35% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Alta (8.7) | 0.44% | — | Line Android APPAI | 4/8/2026 | 28/8/2026 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause… | |
| Aplazada | Baja (0.9) | 0.11% | — | Meesho Online Shopping APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Exchange Online | 24/7/2026 | 29/7/2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |