Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
14.300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.43% | — | Raider SpiritAI | 17/6/2026 | 6/10/2026 | Inclusión local de ficheros no autenticada en versiones de Raider Spirit menor o igual a 1.1.2. | |
| Analizada | Crítica (9.1) | 0.29% | — | Langchain Langgraph-sdk | 17/6/2026 | 26/6/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Analizada | Media (6.8) | 0.69% | — | Langchain Langgraph-checkpoint | 16/6/2026 | 24/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest… | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Alta (7.4) | 0.28% | — | Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Aplazada | Alta (8.2) | 0.37% | — | Maian SearchAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | RepairbuddyAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Speakout Email PetitionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paid Member SubscriptionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | YaymailAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | |
| Aplazada | Alta (7.2) | 0.46% | — | AI EngineAI | 15/6/2026 | 17/6/2026 | Editor Privilege Escalation in AI Engine <= 3.4.9 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Paid Videochat Turnkey SiteAI | 15/6/2026 | 17/6/2026 | Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions. | |
| Aplazada | Alta (8.1) | 0.35% | — | Mozilla BonsaiAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes. | |
| Aplazada | Alta (7.5) | 0.46% | — | Feuerhamster MailformAI | 15/6/2026 | 17/6/2026 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.42% | — | Vmware Spring AI | 15/6/2026 | 17/6/2026 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix… | |
| Aplazada | Alta (7.5) | 0.42% | — | Ayecode GetpaidAI | 15/6/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49. | |
| Aplazada | Media (6.5) | 0.13% | — | ElizaibotsAI | 15/6/2026 | 7/10/2026 | Cross-Site Scripting (XSS) de Contribuidor en versiones menor o igual a 1.0.2 de Elizaibots. | |
| Analizada | Alta (7.8) | 0.13% | — | Foxit AI | 15/6/2026 | 17/6/2026 | When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution. | |
| Aplazada | Media (5.5) | 0.40% | — | Hkuds Ai-traderAI | 15/6/2026 | 24/7/2026 | Una vulnerabilidad fue encontrada en HKUDS AI-Trader hasta 74caf996f78dcc0c657df8365c8544678a16e215. Esto afecta una parte desconocida del archivo /api/research/agents.csv del componente Research Export. Realizar una manipulación resulta en revelación de información. La explotación remota del ataque es posible. El… | |
| Aplazada | Alta (7.1) | 0.14% | 💥 PoC | Comma AI OpenpilotAI | 14/6/2026 | 24/7/2026 | Se encontró una vulnerabilidad en Comma AI Openpilot 0.11. Este problema afecta a la función pickle.load/pickle.loads del archivo selfdrive/modeld/modeld.py del componente Módulo Pickle. La manipulación resulta en deserialización. El ataque solo es posible con acceso local. El proveedor fue contactado tempranamente… |