Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (1.1)0.20%—Wikimedia Mediawiki CollectionAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
Pendiente de análisisMedia (6.1)0.15%—Wikimedia CollectionAI29/9/20261/10/2026
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.
Pendiente de análisisAlta (8.7)0.65%—Amazon PgcollectionAI24/9/202625/9/2026
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval…
AplazadaBaja (2.9)0.12%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.
AplazadaBaja (2.9)0.11%—Portable Puzzle CollectionAI14/9/202622/9/2026
An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
AplazadaBaja (2.9)0.12%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.
AplazadaBaja (2.9)0.10%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.
AplazadaBaja (2.9)0.12%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
AplazadaBaja (2.9)0.12%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
AplazadaBaja (2.9)0.11%—Portable Puzzle CollectionAI14/9/202622/9/2026
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.
AnalizadaMedia (5.9)0.09%—Samsung Collection9/9/202623/9/2026
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
AnalizadaAlta (8.3)0.14%—Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+45/8/202626/8/2026
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes.
Pendiente de análisisMedia (5.5)0.14%—Ansible-collection-redhat-leappAI30/7/20263/8/2026
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive…
Pendiente de análisisMedia (6.2)0.38%—Ansible-collection-redhat-leappAI30/7/20263/8/2026
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed…
AnalizadaAlta (8.8)0.43%—Oracle Advanced Collections21/7/202617/8/2026
Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections.…
AplazadaMedia (6.8)0.47%—NocobaseAINocobase Plugin Collection SQLAI15/7/202616/7/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that…
AnalizadaCrítica (9.1)0.81%—Zie619 N8N Workflow Collection26/8/202520/8/2026
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
AnalizadaMedia (4.3)0.25%—Smackcoders Lead Form Data Collection TO CRM2/7/202517/6/2026
The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (8.8)0.35%—Smackcoders Lead Form Data Collection TO CRMAI23/5/202517/6/2026
Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1.
AplazadaMedia (6)0.17%—Arctera Enterprise Vault Collection ModuleAIVeritas Ediscovery PlatformAI15/4/202517/6/2026
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.
AplazadaMedia (6.5)0.24%—URI Lazcano Ekiline Block CollectionAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Lazcano Ekiline Block Collection ekiline-block-collection allows DOM-Based XSS.This issue affects Ekiline Block Collection: from n/a through <= 1.0.5.
AplazadaMedia (6.5)0.32%—Agnel Waghela Shortcode CollectionAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agnel Waghela Shortcode Collection shortcode-collection allows Stored XSS.This issue affects Shortcode Collection: from n/a through <= 1.4.
AnalizadaMedia (6.9)0.75%—Sadat Garbage Collection Management System24/10/202417/6/2026
A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.53%—Home Owners Collection Management System Project Home Owners Collection Management System2/7/202417/6/2026
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaMedia (5.3)0.68%—Home Owners Collection Management System Project Home Owners Collection Management System2/7/202417/6/2026
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has…