Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.53% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. These logs may contain… | |
| Aplazada | Crítica (10) | 0.61% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin… | |
| Aplazada | Media (5.7) | 0.16% | — | Onelogin AD ConnectorAI | 1/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing… | |
| Analizada | Crítica (10) | 39% | 💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent… | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Aplazada | Media (6.7) | 0.10% | — | Aveva PI Connector FOR CygnetAI | 12/6/2025 | 17/6/2026 | An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a miscreant with elevated privileges to modify PI Connector for CygNet local data files (cache and buffers) in a way that causes the connector service to… | |
| Aplazada | Media (6.9) | 0.15% | — | Aveva PI Connector FOR CygnetAI | 12/6/2025 | 17/6/2026 | A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages. | |
| Analizada | Alta (7.2) | 0.51% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 4/6/2025 | 17/6/2026 | A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An… | |
| Aplazada | Alta (7.3) | 0.10% | — | Zscaler Client ConnectorAI | 4/6/2025 | 17/6/2026 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. | |
| Aplazada | Alta (7) | 0.30% | — | Amazon Redshift Python ConnectorAI | 27/5/2025 | 17/6/2026 | When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. This issue has… | |
| Aplazada | Media (4.3) | 0.23% | — | Sharespine Woocommerce ConnectorAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharespine Woocommerce Connector: from n/a through <= 4.7.55. | |
| Analizada | Media (5.4) | 0.18% | — | Westerndeal Easy Digital Downloads Google Sheet ConnectorEDD Gsheetconnector | 15/5/2025 | 17/6/2026 | The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Analizada | Alta (8.7) | 1.1% | 💥 PoC | Forescout Secureconnector | 13/5/2025 | 17/6/2026 | A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting… | |
| Analizada | Baja (3.3) | 0.17% | — | Snowflake Connector FOR C/c++ | 29/4/2025 | 17/6/2026 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in… | |
| Analizada | Baja (3.3) | 0.12% | — | Snowflake Connector FOR C/c++ | 29/4/2025 | 17/6/2026 | libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of… | |
| Analizada | Alta (7) | 0.17% | — | Snowflake Connector | 28/4/2025 | 17/6/2026 | snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads logging configuration from a user-provided file. On Linux and… | |
| Analizada | Alta (7) | 0.17% | — | Snowflake Connector | 28/4/2025 | 17/6/2026 | snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and… | |
| Analizada | Media (4.8) | 0.40% | — | Oracle Mysql Connector/python | 15/4/2025 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Analizada | Alta (7.5) | 0.61% | — | Oracle Mysql Connector/j | 15/4/2025 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Aplazada | Alta (7.1) | 0.42% | — | Jaap Jansma Connector TO Civicrm With CivimcrestfaceAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface allows Reflected XSS.This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through <= 1.0.8. | |
| Aplazada | Media (5.3) | 0.28% | — | Jaap Jansma Connector TO Civicrm With CivimcrestfaceAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace connector-civicrm-mcrestface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through <= 1.0.10. | |
| Aplazada | Media (4.3) | 0.14% | — | Apimo ConnectorAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Proptech Plugin Apimo Connector apimo allows Cross Site Request Forgery.This issue affects Apimo Connector: from n/a through <= 2.6.5.1. | |
| Aplazada | Media (6.5) | 0.29% | — | LeadconnectorAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadConnector LeadConnector leadconnector allows DOM-Based XSS.This issue affects LeadConnector: from n/a through <= 3.0.2. | |
| Modificada | Media (5.3) | 0.62% | — | Bigbuy Dropshipping Connector FOR Woocommerce | 18/2/2025 | 17/6/2026 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.40% | — | Westerndeal CF7 Google Sheets ConnectorAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from n/a through <= 5.0.17. |