Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
572 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.54% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | TWO FactorAI | 30/9/2026 | 30/9/2026 | Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. | |
| Aplazada | Alta (8.1) | 0.21% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to… | |
| Aplazada | Baja (3.3) | 0.13% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting… | |
| Pendiente de análisis | Baja (2.3) | 0.16% | — | Keyfactor SignserverAI | 15/9/2026 | 22/9/2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can reveal information to the client side. Three specific properties were identified: The… | |
| Pendiente de análisis | Media (4.9) | 0.39% | — | Keyfactor SignserverAI | 15/9/2026 | 22/9/2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the… | |
| Pendiente de análisis | Baja (2.7) | 0.29% | — | Keyfactor SignserverAI | 15/9/2026 | 22/9/2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server… | |
| Aplazada | Alta (8.7) | 0.51% | — | Llama FactoryAI | 4/9/2026 | 24/9/2026 | LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and re-resolves DNS without re-validation,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Webfactoryltd Under ConstructionAI | 3/9/2026 | 7/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | |
| Aplazada | Alta (7.1) | 0.35% | — | Factorfx OCS InventoryAI | 3/9/2026 | 3/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make… | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Rockwellautomation Factorytalk Activation ManagerAI | 1/9/2026 | 1/9/2026 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack… | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. | |
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa | Jfrog Artifactory | 28/8/2026 | 3/9/2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Jfrog ArtifactoryAI | 25/8/2026 | 28/8/2026 | An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions. | |
| Pendiente de análisis | Baja (3.5) | 0.29% | — | Jfrog ArtifactoryAICocoapodsAI | 25/8/2026 | 28/8/2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (10) | 0.52% | — | Link FactoryAI | 13/8/2026 | 26/8/2026 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check). | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Analizada | Alta (8.8) | 0.52% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |
| Analizada | Alta (7.5) | 9.8% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 1/10/2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | |
| Analizada | Media (4.3) | 0.28% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An authenticated user without repository read permission may access package metadata under specific conditions. | |
| Analizada | Media (5.9) | 0.41% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |
| Analizada | Alta (8.1) | 0.20% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. |