Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

14.300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.43%—Raider SpiritAI17/6/20266/10/2026
Inclusión local de ficheros no autenticada en versiones de Raider Spirit menor o igual a 1.1.2.
AnalizadaCrítica (9.1)0.29%—Langchain Langgraph-sdk17/6/202626/6/2026
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without…
AnalizadaAlta (7.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul17/6/202618/6/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalizadaAlta (7.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul17/6/202618/6/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalizadaAlta (8.5)0.33%—Oracle Complex Maintenance Repair AND Overhaul17/6/202618/6/2026
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex…
AnalizadaMedia (6.8)0.69%—Langchain Langgraph-checkpoint16/6/202624/6/2026
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest…
AplazadaCrítica (9.8)0.56%💥 PoCIntegration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
AplazadaCrítica (9.8)0.56%—Integration FOR Mailchimp AND Contact Form 7AI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (7.5)0.48%—Omnisend Email Marketing FOR WoocommerceAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
AplazadaAlta (8.2)0.37%—Maian SearchAI15/6/202617/6/2026
Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 versions.
AplazadaMedia (6.5)0.34%—RepairbuddyAI15/6/202617/6/2026
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
AplazadaCrítica (9.3)0.40%—Speakout Email PetitionsAI15/6/202617/6/2026
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
AplazadaAlta (7.1)0.25%—Paid Member SubscriptionsAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
AplazadaAlta (7.2)0.54%—YaymailAI15/6/202617/6/2026
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
AplazadaAlta (7.2)0.46%—AI EngineAI15/6/202617/6/2026
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
AplazadaAlta (8.1)0.44%—Paid Videochat Turnkey SiteAI15/6/202617/6/2026
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
AplazadaAlta (8.1)0.35%—Mozilla BonsaiAI15/6/202617/6/2026
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.
AplazadaAlta (7.5)0.46%—Feuerhamster MailformAI15/6/202617/6/2026
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.42%—Vmware Spring AI15/6/202617/6/2026
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix…
AplazadaAlta (7.5)0.42%—Ayecode GetpaidAI15/6/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.
AplazadaMedia (6.5)0.13%—ElizaibotsAI15/6/20267/10/2026
Cross-Site Scripting (XSS) de Contribuidor en versiones menor o igual a 1.0.2 de Elizaibots.
AnalizadaAlta (7.8)0.13%—Foxit AI15/6/202617/6/2026
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
AplazadaMedia (5.5)0.40%—Hkuds Ai-traderAI15/6/202624/7/2026
Una vulnerabilidad fue encontrada en HKUDS AI-Trader hasta 74caf996f78dcc0c657df8365c8544678a16e215. Esto afecta una parte desconocida del archivo /api/research/agents.csv del componente Research Export. Realizar una manipulación resulta en revelación de información. La explotación remota del ataque es posible. El…
AplazadaAlta (7.1)0.14%💥 PoCComma AI OpenpilotAI14/6/202624/7/2026
Se encontró una vulnerabilidad en Comma AI Openpilot 0.11. Este problema afecta a la función pickle.load/pickle.loads del archivo selfdrive/modeld/modeld.py del componente Módulo Pickle. La manipulación resulta en deserialización. El ataque solo es posible con acceso local. El proveedor fue contactado tempranamente…