Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

11.348 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.3)0.29%—Drupal ScreenshotAI2/9/20265/10/2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
AplazadaAlta (8.5)0.17%—KongaAIOpensslAI1/9/20268/9/2026
Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a…
Pendiente de análisisAlta (7.5)0.79%—Openshift Oauth-serverAIGolang.org X TextAI1/9/20267/10/2026
A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the…
Pendiente de análisisAlta (8.7)0.96%—Opensearch SQLAI31/8/20263/9/2026
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
AplazadaBaja (2.1)0.22%—Toggl Track ExtensionAI31/8/202631/8/2026
A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The…
AplazadaBaja (1.9)0.15%—Extension.vn 2FA Authenticator ExtensionAI31/8/20262/9/2026
A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack…
AplazadaBaja (2.1)0.45%—Vidiq Vision FOR Youtube ExtensionAI31/8/20261/9/2026
A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure. The attack is possible to be carried…
AplazadaMedia (5.5)0.47%—Inbox Foundry Activeinbox ExtensionAI31/8/202631/8/2026
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The…
AplazadaAlta (8.8)0.54%—JoomlaAIMinirange ExtensionsAI31/8/20268/9/2026
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
AplazadaAlta (8.7)0.76%—DocumensoAI29/8/202624/9/2026
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
Pendiente de análisisMedia (5.5)0.16%—Fedora DNFAISuse ZypperAIRedhat YUMAIOpensuse LibsolvAI28/8/202628/8/2026
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the…
AplazadaMedia (6.4)0.26%—ALL IN ONE WP Migration Unlimited ExtensionAI28/8/202628/8/2026
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and including, 2.84. This is due to insufficient input sanitization and output escaping on user-supplied attributes combined with missing…
AplazadaMedia (6.9)0.43%—Watchguard DimensionAI28/8/202628/8/2026
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
AplazadaMedia (6.3)0.41%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed…
AplazadaMedia (4.8)0.30%—Watchguard DimensionAI28/8/202628/8/2026
A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.
AplazadaMedia (4.6)0.47%—Watchguard DimensionAI28/8/202628/8/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL.
AplazadaAlta (8.6)0.71%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
AplazadaAlta (8.6)0.62%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
AplazadaAlta (8.6)0.71%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
AplazadaAlta (8.4)0.23%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's…
AplazadaMedia (5.1)0.44%—Watchguard Dimension Database ServerAI28/8/202628/8/2026
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AplazadaMedia (5.1)0.44%—Watchguard DimensionAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AplazadaMedia (5.1)0.44%—Watchguard Dimension Email ServerAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AplazadaMedia (5.3)0.39%—Watchguard DimensionAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AplazadaCrítica (9.3)0.43%—Watchguard DimensionAI28/8/202628/8/2026
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.