Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

3322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.63%—Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI21/8/202626/8/2026
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
AnalizadaCrítica (10)0.80%—Microsoft Azure ARC20/8/202624/8/2026
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (8.7)0.66%—Opensearch DashboardsAI20/8/202625/8/2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code…
AplazadaAlta (7.1)0.25%—Themehunk Advance Product SearchAI20/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
AnalizadaAlta (7.1)0.87%—Tp-link Tl-mr100 FirmwareTp-link Archer Mr600 FirmwareTp-link Tl-mr150 FirmwareTp-link Tl-mr6400 Firmware20/8/20263/9/2026
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated…
Pendiente de análisisMedia (6.8)0.53%—Search-indexerAI19/8/20265/9/2026
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the…
AnalizadaAlta (8.5)2.8%💥 PoCTp-link Archer C20 Firmware19/8/20268/9/2026
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device…
Pendiente de análisisCrítica (9.9)0.55%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive…
Pendiente de análisisCrítica (9.1)0.71%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a…
AplazadaAlta (8.3)0.35%—ArcadedbAI19/8/20268/9/2026
ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and…
AplazadaAlta (8.7)0.85%—ArcadedbAIArcadedb-gremlinAI19/8/20268/9/2026
ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a…
AplazadaAlta (7.1)0.35%—ArcadedbAI19/8/20268/9/2026
ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling…
AplazadaCrítica (9.3)0.40%—Wpo-hr NGG Smart Image SearchAI19/8/202620/8/2026
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
AnalizadaAlta (8.1)0.39%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AnalizadaAlta (7.5)0.41%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided…
AnalizadaMedia (5.5)0.15%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
AnalizadaAlta (7.2)0.27%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaMedia (6.1)0.24%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (7.2)0.27%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (7.8)0.16%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle…
AnalizadaAlta (7.6)0.27%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
AnalizadaCrítica (9.1)0.43%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaMedia (6.1)0.24%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202631/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaAlta (8.2)0.44%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202624/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AnalizadaAlta (7.5)0.35%—Oracle Commerce Experience ManagerOracle Commerce Guided Search18/8/202624/8/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…