Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

572 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.54%—Wpfactory Cost OF Goods FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
AplazadaMedia (5.3)0.40%—TWO FactorAI30/9/202630/9/2026
Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
AplazadaAlta (8.1)0.21%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to…
AplazadaBaja (3.3)0.13%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting…
Pendiente de análisisBaja (2.3)0.16%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can be set to by an admin user. Setting these properties to specific file paths can reveal information to the client side. Three specific properties were identified: The…
Pendiente de análisisMedia (4.9)0.39%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the…
Pendiente de análisisBaja (2.7)0.29%—Keyfactor SignserverAI15/9/202622/9/2026
An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server…
AplazadaAlta (8.7)0.51%—Llama FactoryAI4/9/202624/9/2026
LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and re-resolves DNS without re-validation,…
AplazadaAlta (7.1)0.25%—Webfactoryltd Under ConstructionAI3/9/20267/9/2026
Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
AplazadaAlta (7.1)0.35%—Factorfx OCS InventoryAI3/9/20263/9/2026
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make…
Pendiente de análisisAlta (8.5)0.11%—Rockwellautomation Factorytalk Activation ManagerAI1/9/20261/9/2026
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack…
Pendiente de análisisMedia (4.8)0.16%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Pendiente de análisisAlta (8.6)0.31%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.
AnalizadaCrítica (9.8)14%⚠ Explotación activaJfrog Artifactory28/8/20263/9/2026
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Pendiente de análisisMedia (6.5)0.35%—Jfrog ArtifactoryAI25/8/202628/8/2026
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
Pendiente de análisisBaja (3.5)0.29%—Jfrog ArtifactoryAICocoapodsAI25/8/202628/8/2026
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
AnalizadaAlta (7.5)0.97%—Microsoft Azure Data Factory20/8/202624/8/2026
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.53%—Microsoft Azure Data Factory20/8/202624/8/2026
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (10)0.52%—Link FactoryAI13/8/202626/8/2026
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
AplazadaCrítica (9.8)0.50%—Wpfactory Customer Email Verification FOR WoocommerceAI13/8/202626/8/2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered…
AnalizadaAlta (8.8)0.52%—Jfrog Artifactory12/8/202611/9/2026
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
AnalizadaAlta (7.5)9.8%⚠ Explotación activaJfrog Artifactory12/8/20261/10/2026
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
AnalizadaMedia (4.3)0.28%—Jfrog Artifactory12/8/202611/9/2026
An authenticated user without repository read permission may access package metadata under specific conditions.
AnalizadaMedia (5.9)0.41%—Jfrog Artifactory12/8/202611/9/2026
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
AnalizadaAlta (8.1)0.20%—Jfrog Artifactory12/8/202611/9/2026
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.