Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1096 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an excessively large memory allocation,…
AnalizadaAlta (8.8)0.60%—Elasticsearch13/8/20261/9/2026
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable index can submit one small search request…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analysis definition that is resolved…
AnalizadaMedia (6.5)0.42%—Elasticsearch13/8/20261/9/2026
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations…
Pendiente de análisisAlta (8.7)1.00%—Opensearch SQL PluginAIApache SparkAI13/8/202614/8/2026
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
Pendiente de análisisCrítica (9)1.2%—Redhat ACM Search V2 Rhel9AI12/8/202627/8/2026
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all…
Pendiente de análisisAlta (7.5)0.74%—Search-v2-apiAI12/8/202627/8/2026
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a…
Pendiente de análisisAlta (8.6)0.58%—Amazon OpensearchAIAmazon Opensearch AlertingAI12/8/202613/8/2026
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Pendiente de análisisAlta (8.6)0.52%—Opensearch Security AnalyticsAI12/8/202621/8/2026
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
AplazadaAlta (8.4)0.40%—Fujitsu Research OnecompressionAI12/8/202624/9/2026
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking…
Pendiente de análisisMedia (5.3)0.42%—Acm-search-v2-api-rhel9AI11/8/20265/9/2026
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results,…
Pendiente de análisisAlta (7.5)0.83%—Search-v2-apiAI11/8/202626/8/2026
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the…
AplazadaAlta (8.2)0.66%—Telegram-searchAI11/8/202624/9/2026
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly…
AplazadaBaja (1.9)0.16%—Adenot Mcp-google-searchAI9/8/202612/8/2026
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called…
AplazadaCrítica (9.8)0.85%—Ajax Search LiteAI7/8/202626/8/2026
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to…
AplazadaMedia (5.9)0.24%—FibosearchAI6/8/202612/8/2026
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
AplazadaCrítica (9.8)0.56%—Ajax Search LiteAI6/8/202612/8/2026
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and…
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been…
AplazadaAlta (8.1)0.27%—Search Analytics FOR WPAI5/8/202612/8/2026
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete…
AplazadaBaja (2.1)0.38%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been…
AplazadaBaja (2.1)0.35%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published…
AplazadaBaja (2.1)0.35%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and…
AplazadaMedia (5.4)0.29%—Search Atlas SEOAI30/7/202630/7/2026
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing…
Orbitaley — Vulnerabilidades