Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

2202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.40%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map…
AnalizadaAlta (7.5)0.46%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To…
AnalizadaAlta (7.5)0.22%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and…
AnalizadaCrítica (9.8)0.35%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain…
AnalizadaBaja (3.1)0.27%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and…
AnalizadaMedia (6.5)0.16%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF…
AnalizadaAlta (8.2)0.32%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further…
AnalizadaMedia (5.3)0.33%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every…
AnalizadaAlta (7.2)0.28%—Hcltech Dfxanalytics16/7/202617/7/2026
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session…
Pendiente de análisisMedia (6.9)0.42%—Strands Agents ToolsAIElasticsearchAI15/7/202615/7/2026
Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the…
AplazadaAlta (8.7)0.44%—Joomla 4analyticsAI15/7/202623/7/2026
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
AplazadaAlta (8.6)0.44%—Joomla 4analyticsAI15/7/202623/7/2026
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature.
AplazadaMedia (6.5)0.59%—Majesticsupport Majestic SupportAI11/7/202613/7/2026
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AnalizadaMedia (5.4)0.23%—Ijsbrandy Siteimprove Analytics10/7/20266/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1.
AplazadaCrítica (9.8)0.58%—Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026.
AplazadaMedia (5.4)0.23%—Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.
AplazadaMedia (6.5)0.38%—Nomysoft Informatics Education AND Consulting INC NomysemAI8/7/20268/7/2026
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did…
AplazadaBaja (2.9)0.40%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20266/7/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as…
AplazadaBaja (2.1)0.37%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20267/7/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote…
AplazadaAlta (7.1)0.25%—TimeticsAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
AplazadaCrítica (9.8)0.56%—BookticsAI2/7/20262/7/2026
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
AnalizadaMedia (6.5)0.42%—Elasticsearch1/7/20262/7/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.
AnalizadaMedia (4.9)0.50%—Elasticsearch1/7/20262/7/2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node…
AnalizadaMedia (6.5)0.47%—Elasticsearch1/7/20262/7/2026
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.
AplazadaMedia (4.3)0.15%—IO Technologies Plugin FOR Google AnalyticsAI30/6/202630/6/2026
The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible for unauthenticated attackers to update…