Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.1)——Ivorysearch Ivory SearchAI3/10/20263/10/2026
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.7)1.0%—Tp-link Archer Ax90AI1/10/20262/10/2026
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot. Successful exploitation may result in complete device…
AplazadaAlta (7.1)0.36%—4TU Researchdata DjehutyAI1/10/20262/10/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:…
AplazadaAlta (8.4)0.30%—4tu.researchdata DjehutyAI1/10/20262/10/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.…
Pendiente de análisisBaja (1.2)0.30%—Wikimedia MediasearchAI30/9/20261/10/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.
AplazadaAlta (7.1)0.18%—Yithemes Yith Woocommerce Ajax SearchAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
AplazadaMedia (5.5)0.41%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried…
AplazadaMedia (5.5)0.40%—Trusteddomain OpendmarcAI28/9/202629/9/2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used.…
AplazadaMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202629/9/2026
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The…
AplazadaBaja (2.1)0.13%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit…
Pendiente de análisisMedia (6.9)0.39%—Marcos Camara01 Ecommerce TemplateAI28/9/202629/9/2026
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The…
AplazadaAlta (8.8)0.24%—Iron Mountain Archiving Services EnvisionAI28/9/202628/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
Pendiente de análisisMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could…
Pendiente de análisisMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of…
Pendiente de análisisMedia (5.5)0.29%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has…
Pendiente de análisisMedia (5.5)0.31%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely.…
Pendiente de análisisMedia (5.4)0.11%—Google Fuse-archiveAI28/9/202629/9/2026
In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user…
AplazadaMedia (5.7)0.33%—Barco Clickshare Cx-20 Gen2AI28/9/202628/9/2026
A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be…
AplazadaMedia (5.5)0.67%—Trusted Domain Project OpenarcAI28/9/202628/9/2026
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released…
Pendiente de análisisMedia (5.5)0.29%—Trusteddomain OpendmarcAI27/9/20261/10/2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch…
Pendiente de análisisMedia (5.5)0.37%—Trusteddomain OpendmarcAI27/9/202628/9/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the…
En análisisMedia (4.9)0.44%—ElasticsearchAI26/9/202628/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)