Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.49% | — | Kagisearch SmallwebAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be… | |
| Analizada | Media (6.1) | 0.34% | — | Andisearch | 30/7/2025 | 17/6/2026 | andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Aplazada | Media (6.1) | 0.13% | — | Xisearch BARAI | 14/6/2025 | 17/6/2026 | The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts… | |
| Aplazada | Alta (7) | 0.40% | — | RedisearchAI | 8/1/2025 | 17/6/2026 | RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT command argument, or FT.SEARCH with a specially crafted KNN command argument, can trigger an integer overflow, leading… | |
| Modificada | Alta (7.5) | 1.2% | — | Openbsd Textproc/isearch | 30/12/2019 | 16/6/2026 | The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp). | |
| Modificada | Alta (7.5) | 2.8% | — | Isearch | 11/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5) google_sitemap.php, (6) stats.php, or (7) auto_spider_img.php. NOTE: this issue… | |
| Modificada | Alta (7.5) | 2.8% | — | IsearchAI | 31/12/2004 | 16/6/2026 | PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary code via the isearch_path parameter. | |
| Modificada | Crítica (9.8) | 5.7% | — | RisearchRisearch PRO | 27/7/2004 | 16/6/2026 | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL. |