Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.24%—Boks KsllogsdAI1/10/20261/10/2026
boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized,…
AplazadaAlta (8.8)0.29%—Innotim Logsign SiemAI28/9/202628/9/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
AplazadaAlta (7.1)0.28%—Innotim Logsign SiemAI28/9/202628/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
AplazadaCrítica (9.8)0.27%—Innotim Software Telecommunications AND Consultancy Trade Logsign SiemAI28/9/202628/9/2026
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Pendiente de análisisAlta (7.1)0.39%—MalcolmAIOpensearchAIElastic LogstashAIArkimeAI+118/8/20268/9/2026
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma,…
AplazadaCrítica (9)0.41%—Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI17/8/202626/8/2026
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
AplazadaCrítica (9.8)0.56%—Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI31/7/202626/8/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.
AplazadaAlta (8.7)0.35%—LogseqAI9/6/202623/7/2026
Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, `grep`), the argument string is concatenated with the command and passed to `child_process.spawn` with the `shell: true` option, allowing shell metacharacters…
AplazadaMedia (4.6)0.19%—LogseqAI9/6/202623/7/2026
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to execute arbitrary JavaScript in the…
AplazadaMedia (4.6)0.20%—LogseqAI9/6/202623/7/2026
Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" without proper sanitization, allowing the execution of arbitrary code in the privileged host context. While only version…
AplazadaAlta (8.7)0.18%—LogseqAI9/6/202623/7/2026
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript execution in the renderer (e.g. via XSS or a malicious plugin), can read, write, or delete arbitrary files on the user's system. While only…
AplazadaAlta (7.5)0.42%—Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI1/6/202622/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a…
Pendiente de análisisCrítica (9.8)0.84%—Crowdstrike LogscaleAI21/4/202617/6/2026
CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific…
AnalizadaCrítica (9.8)0.85%—Elastic Logstash8/4/202624/7/2026
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker…
AplazadaMedia (4.3)0.12%—WpblogsynAI14/1/202617/6/2026
The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's remote sync settings via a forged request granted they can trick a site…
AplazadaMedia (6.4)0.22%—Divelogs WidgetAI12/12/202517/6/2026
The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.4)0.15%—Secuavail Logstare Collector21/11/202517/6/2026
Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer.
AnalizadaMedia (6.9)0.26%—Secuavail Logstare Collector21/11/202517/6/2026
LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.
AnalizadaMedia (6.9)0.14%—Secuavail Logstare Collector21/11/202517/6/2026
Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.
AnalizadaMedia (5.3)0.23%—Secuavail Logstare Collector21/11/202517/6/2026
LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.
AnalizadaMedia (4.8)0.17%—Secuavail Logstare Collector21/11/202517/6/2026
LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
AnalizadaMedia (6.8)0.12%—Secuavail Logstare Collector21/11/202517/6/2026
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.
AnalizadaMedia (6.2)0.40%—Cnblogs Pdfpatcher17/11/202517/6/2026
PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.
AnalizadaAlta (7.1)0.40%—Cnblogs Pdfpatcher17/11/202517/6/2026
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive…
AplazadaAlta (7.1)0.13%—Johnh10 Video Blogster LiteAI22/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2.