Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Pendiente de análisis | Alta (7.2) | 0.33% | — | Openshift ConsoleAIOpenshift CatalogdAI | 23/9/2026 | 1/10/2026 | A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the… | |
| Aplazada | Alta (7.1) | 0.35% | — | Pixelyoursite EDD Product Catalog FeedAI | 8/9/2026 | 8/9/2026 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.33% | — | Multivendorx Product Catalog Enquiry FOR WoocommerceAI | 8/9/2026 | 25/9/2026 | Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 6.1.5. | |
| Aplazada | Media (4.3) | 0.15% | — | CatalogxAI | 2/9/2026 | 3/9/2026 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an… | |
| Aplazada | Media (6.4) | 0.36% | — | Implecode Ecommerce Product CatalogAI | 25/8/2026 | 28/9/2026 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Communications Service Catalog AND Design | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solution Designer). Supported versions that are affected are 8.0.0.7.0-8.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (7.1) | 0.25% | — | Implecode Ecommerce Product CatalogAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Implecode Ecommerce Product CatalogAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | |
| Aplazada | Alta (8.7) | 0.32% | — | Wpultimate Wordpress Ultimate Product CatalogAI | 15/6/2026 | 17/6/2026 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file… | |
| Aplazada | Alta (8.8) | 0.27% | — | Product Catalog 8AI | 9/6/2026 | 21/7/2026 | Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList… | |
| Analizada | Media (5.5) | 0.07% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Media (5.5) | 0.10% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | |
| Analizada | Alta (7.5) | 0.13% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.8) | 0.09% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (5.5) | 0.10% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | |
| Analizada | Media (6.5) | 0.08% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 22/5/2026 | 23/7/2026 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing… | |
| Analizada | Alta (7.5) | 0.35% | — | Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack | 20/5/2026 | 23/7/2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (4.3) | 0.20% | — | Games CatalogAI | 20/5/2026 | 23/7/2026 | The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the gc_crud() function which handles the delete action (action=delete) via a GET request without any wp_verify_nonce() /… | |
| Analizada | Media (4.3) | 0.28% | — | Linuxfoundation Backstage/plugin-catalog-backend-module-unprocessedLinuxfoundation Backstage/plugin-catalog-unprocessed-entitiesLinuxfoundation Backstage/plugin-catalog-unprocessed-entities-common | 14/5/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.1) | 0.28% | — | Ultimate Product CatalogueAI | 10/5/2026 | 25/7/2026 | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product… | |
| Analizada | Media (4.4) | 0.15% | — | IBM Knowledge Catalog | 25/3/2026 | 17/6/2026 | IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores potentially sensitive information in log files that could be read by a local privileged user. |