Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | IBM Engineering Lifecycle Management | 17/7/2026 | 11/8/2026 | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Aplazada | Media (5.9) | 0.23% | — | AI EngineAI | 16/7/2026 | 16/7/2026 | The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled. | |
| Aplazada | Media (5.4) | 0.23% | — | TdengineAI | 15/7/2026 | 15/7/2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied.… | |
| Aplazada | Media (5.4) | 0.33% | — | TdengineAI | 15/7/2026 | 15/7/2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL… | |
| Aplazada | Alta (7.5) | 0.46% | — | TdengineAI | 15/7/2026 | 15/7/2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packet contained the 8-byte STransCompMsg structure, causing an… | |
| Aplazada | Alta (7.2) | 0.54% | — | TdengineAI | 15/7/2026 | 18/7/2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbitrary C code on the TDengine server side through database… | |
| Aplazada | Alta (8.3) | 0.57% | — | TdengineAI | 15/7/2026 | 15/7/2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte out-of-bounds write to the stack buffer… | |
| Aplazada | Media (5.4) | 0.29% | — | TdengineAI | 15/7/2026 | 16/7/2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL SSMIGRATE <id> against an active shared-storage migration because mndProcessKillSsMigrateReq called mndKillSsMigrate while the intended… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Malware Protection Engine | 14/7/2026 | 24/7/2026 | Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Malware Protection Engine | 14/7/2026 | 24/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. | |
| Aplazada | Alta (8.1) | 0.47% | — | AI EngineAI | 14/7/2026 | 14/7/2026 | The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal. | |
| Aplazada | Media (6.5) | 0.33% | — | Roxnor Wp-fundraising-donationAIWpmet FundengineAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6. | |
| Aplazada | Alta (8.8) | 0.85% | — | Code EngineAI | 11/7/2026 | 29/9/2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 0.64% | — | Socket Engine.io | 8/7/2026 | 13/7/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust… | |
| Analizada | Alta (7.5) | 0.61% | — | Socket Engine.io | 8/7/2026 | 13/7/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and… | |
| Analizada | Media (6) | 0.27% | — | Hasura Graphql Engine | 7/7/2026 | 17/8/2026 | Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's row-level permissions. While such rows cannot be… | |
| Pendiente de análisis | Alta (7.1) | 0.57% | — | Amazon Research AND Engineering StudioAI | 7/7/2026 | 8/7/2026 | AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read… | |
| Aplazada | Media (4.6) | 0.24% | — | Wptravelengine WP Travel EngineAI | 7/7/2026 | 9/7/2026 | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image… | |
| Aplazada | Alta (7.4) | 0.17% | — | E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI | 1/7/2026 | 1/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12. | |
| Aplazada | Media (6.1) | 0.25% | — | Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI | 30/6/2026 | 30/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Eksagate Electronic Engineering AND Computer Industry Trade Sysguard 6001AI | 30/6/2026 | 30/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0. NOTE: The vendor was contacted and it was… | |
| Aplazada | Baja (2.3) | 0.18% | — | Volcengine OpenvikingAI | 28/6/2026 | 29/6/2026 | A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data… |