Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2776▲ 17 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
2202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.38% | — | IBM Planning Analytics Local | 30/7/2026 | 12/8/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. | |
| Analizada | Media (6.3) | 0.26% | — | IBM Operations Analytics - LOG Analysis | 30/7/2026 | 1/10/2026 | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, y 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 no invalida la sesión después de un cambio de contraseña, lo que podría permitir a un usuario autenticado suplantar a otro usuario en el sistema. | |
| Aplazada | Media (5.3) | 0.34% | — | Shinystat AnalyticsAI | 29/7/2026 | 30/7/2026 | The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products. | |
| Aplazada | Alta (8.7) | 0.22% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and… | |
| Aplazada | Alta (7.7) | 0.19% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session.… | |
| Aplazada | Alta (8.7) | 0.31% | — | Ghostrobotics Vision 60AIGhostrobotics Vision 60 Mobile APPAI | 27/7/2026 | 27/7/2026 | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can… | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.47% | 💥 PoC | Xpoda Turkiye Informatics Technology INC NO Code PlatformAI | 22/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4. | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 22/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource exhaustion persists… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 3/8/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation… | |
| Analizada | Media (6.7) | 0.43% | — | Oracle Product Lifecycle Analytics | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.… | |
| Analizada | Crítica (9.3) | 0.44% | — | Oracle Product Lifecycle Analytics | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While… | |
| Analizada | Crítica (9) | 0.19% | — | Oracle Product Lifecycle Analytics | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes… | |
| Analizada | Baja (3.3) | 0.15% | — | Oracle Goldengate Stream Analytics | 21/7/2026 | 6/8/2026 | Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 21/7/2026 | 7/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory… | |
| Analizada | Media (6.5) | 0.32% | — | Elasticsearch | 21/7/2026 | 26/8/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest… | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. | |
| Aplazada | Alta (7.5) | 0.35% | — | Wp-slimstat Slimstat AnalyticsAI | 20/7/2026 | 20/7/2026 | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browser of an administrator who views the reports. Exploitation… | |
| Analizada | Media (4.2) | 0.17% | — | IBM Cognos Analytics | 17/7/2026 | 11/8/2026 | IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures due to a race condition in the Agentic AI assistant's concurrent request-handling logic when multiple authenticated users submit… | |
| Analizada | Crítica (9.8) | 0.46% | — | IBM AgenticsIBM DB2 Genius HUB | 17/7/2026 | 11/8/2026 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Pendiente de análisis | Baja (3.3) | 0.10% | — | HCL DfmproAIHCL DfxanalyticsAIHCL DfxserverAI | 17/7/2026 | 29/9/2026 | Los instaladores de HCL DFMPro, DFXAnalytics y DFXServer están afectados por la vulnerabilidad 'Permisos de archivo inseguros que conducen a escalada de privilegios', lo que permite a cualquier usuario no administrativo que haya iniciado sesión sobrescribir o reemplazar el archivo ejecutable con un binario malicioso. |