Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.63% | — | Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI | 21/8/2026 | 26/8/2026 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure ARC | 20/8/2026 | 24/8/2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Opensearch DashboardsAI | 20/8/2026 | 25/8/2026 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code… | |
| Aplazada | Alta (7.1) | 0.25% | — | Themehunk Advance Product SearchAI | 20/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | |
| Analizada | Alta (7.1) | 0.87% | — | Tp-link Tl-mr100 FirmwareTp-link Archer Mr600 FirmwareTp-link Tl-mr150 FirmwareTp-link Tl-mr6400 Firmware | 20/8/2026 | 3/9/2026 | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated… | |
| Pendiente de análisis | Media (6.8) | 0.53% | — | Search-indexerAI | 19/8/2026 | 5/9/2026 | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the… | |
| Analizada | Alta (8.5) | 2.8% | 💥 PoC | Tp-link Archer C20 Firmware | 19/8/2026 | 8/9/2026 | An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device… | |
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive… | |
| Pendiente de análisis | Crítica (9.1) | 0.71% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a… | |
| Aplazada | Alta (8.3) | 0.35% | — | ArcadedbAI | 19/8/2026 | 8/9/2026 | ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and… | |
| Aplazada | Alta (8.7) | 0.85% | — | ArcadedbAIArcadedb-gremlinAI | 19/8/2026 | 8/9/2026 | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.executeStatement() silently falls back to the insecure Groovy engine whenever a… | |
| Aplazada | Alta (7.1) | 0.35% | — | ArcadedbAI | 19/8/2026 | 8/9/2026 | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user with only database access can add or overwrite SQL or Cypher functions in an existing library and persist the change, enabling… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpo-hr NGG Smart Image SearchAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Commerce Guided… | |
| Analizada | Media (5.5) | 0.15% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.2) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle… | |
| Analizada | Alta (7.6) | 0.27% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.2) | 0.44% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Analizada | Alta (7.5) | 0.35% | — | Oracle Commerce Experience ManagerOracle Commerce Guided Search | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… |