Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (2.1) | — | — | Evilmartians ImgproxyAI | 6/10/2026 | 6/10/2026 | A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may… | |
| Pendiente de análisis | Baja (2.1) | 0.44% | — | Artifex GhostscriptAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might… | |
| Aplazada | Alta (7.5) | 0.34% | — | Artifex MujsAI | 24/9/2026 | 25/9/2026 | MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in… | |
| Aplazada | Media (4.3) | 0.35% | — | Partial Shipment FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines… | |
| Pendiente de análisis | Baja (2.1) | 0.59% | — | Artifex MupdfAI | 16/9/2026 | 18/9/2026 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.44% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Articles AnywhereAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust… | |
| Aplazada | Media (5.3) | 0.29% | — | Deposits AND Partial Payments FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | |
| Aplazada | Media (6.9) | 0.41% | — | Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | |
| Aplazada | Alta (8.7) | 0.33% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa | Jfrog Artifactory | 28/8/2026 | 3/9/2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Jfrog ArtifactoryAI | 25/8/2026 | 28/8/2026 | An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions. | |
| Pendiente de análisis | Baja (3.5) | 0.29% | — | Jfrog ArtifactoryAICocoapodsAI | 25/8/2026 | 28/8/2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| Aplazada | Alta (8.7) | 0.35% | — | Actions Upload-artifactAIActions Download-artifactAI | 24/8/2026 | 24/9/2026 | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and… | |
| Aplazada | Alta (8.5) | 1.1% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by… | |
| Aplazada | Alta (8.5) | 1.0% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this… | |
| Aplazada | Media (6.5) | 0.22% | — | Davidartiss Simple-draft-listAI | 18/8/2026 | 20/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This issue affects Draft List: from n/a through 2.6.4. | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle Siebel Artificial Intelligence | 18/8/2026 | 4/9/2026 | Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Artificial Intelligence. While the vulnerability is in… | |
| Aplazada | Media (6) | 0.21% | — | Aotuman Grab Wechat ArticlesAI | 18/8/2026 | 20/8/2026 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | CartifyAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | |
| Aplazada | Alta (7.4) | 0.43% | — | Xnau Participants DatabaseAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | |
| Analizada | Alta (8.8) | 0.52% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |
| Analizada | Alta (7.5) | 9.8% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 1/10/2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |