Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.42%—Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI1/6/202622/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a…
AnalizadaMedia (5.9)0.51%—Apache ActivemqApache Activemq Broker1/6/202622/7/2026
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic…
AnalizadaAlta (8.8)0.63%—Apache Activemq1/6/202622/7/2026
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations…
AnalizadaMedia (4.3)0.50%—Apache ActivemqApache Activemq Broker1/6/202622/7/2026
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6;…
AnalizadaAlta (8.8)0.88%—Apache ActivemqApache Activemq Broker1/6/202621/7/2026
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in…
AnalizadaAlta (8.1)0.66%💥 PoCApache ActivemqApache Activemq Broker1/6/202622/7/2026
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations…
AnalizadaMedia (6.1)0.68%—Apache ActivemqApache Activemq WEB1/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting…
AplazadaCrítica (9.3)1.3%💥 PoCGithub ActionsAISherlockAI27/5/202617/6/2026
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the…
AnalizadaMedia (6.6)0.43%—Jenkins Active Directory27/5/202617/6/2026
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
AnalizadaMedia (6.6)0.37%—Jenkins Active Directory27/5/202617/6/2026
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
AplazadaCrítica (9.3)0.40%—Pluginus Active Products Tables FOR WoocommerceAI27/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9.
AplazadaCrítica (9.3)0.40%—Pluginus Active Products Tables FOR WoocommerceAI27/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8.
AnalizadaMedia (5.6)0.09%—Synology Active Backup FOR Business Agent27/5/20267/10/2026
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
AnalizadaAlta (8.6)0.37%—Synology Active Backup FOR Business27/5/20267/10/2026
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
AnalizadaMedia (5.6)0.09%—Synology Activeprotect Agent27/5/20267/10/2026
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
AplazadaAlta (8.7)0.37%—Owasp FactionAI26/5/202624/7/2026
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output…
AplazadaCrítica (9.8)0.66%—Apache Struts2AIOwasp FactionAI26/5/202620/7/2026
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check…
AplazadaAlta (8.7)0.37%—Owasp FactionAI26/5/202624/7/2026
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attribute contexts…
AnalizadaMedia (6.1)0.19%—IBM Financial Transaction Manager FOR Multiplatform26/5/202624/7/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…
AplazadaMedia (6.5)0.22%—Melapress WP Activity LOGAI25/5/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.
AplazadaBaja (2.1)0.41%—Changmingxie Tcc-transactionAIAlibaba FastjsonAI25/5/202623/7/2026
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not…
AnalizadaAlta (8.6)0.14%—Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+1125/5/202617/8/2026
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.…
AplazadaAlta (8.1)0.66%—Bestpractical RTAI22/5/202623/7/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to…
AplazadaAlta (8.8)0.48%—Bestpractical RTAI22/5/202623/7/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify…
AplazadaAlta (7.1)0.17%—Best Practical Solutions RTAI22/5/202623/7/2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This…
Orbitaley — Vulnerabilidades