Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.24% | — | Boks KsllogsdAI | 1/10/2026 | 1/10/2026 | boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized,… | |
| Aplazada | Alta (8.8) | 0.29% | — | Innotim Logsign SiemAI | 28/9/2026 | 28/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Alta (7.1) | 0.28% | — | Innotim Logsign SiemAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Crítica (9.8) | 0.27% | — | Innotim Software Telecommunications AND Consultancy Trade Logsign SiemAI | 28/9/2026 | 28/9/2026 | Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Pendiente de análisis | Alta (7.1) | 0.39% | — | MalcolmAIOpensearchAIElastic LogstashAIArkimeAI+1 | 18/8/2026 | 8/9/2026 | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma,… | |
| Aplazada | Crítica (9) | 0.41% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 17/8/2026 | 26/8/2026 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Innotim Software Telecommunications AND Consulting Trade Logsign SiemAI | 31/7/2026 | 26/8/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115. | |
| Aplazada | Alta (8.7) | 0.35% | — | LogseqAI | 9/6/2026 | 23/7/2026 | Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, `grep`), the argument string is concatenated with the command and passed to `child_process.spawn` with the `shell: true` option, allowing shell metacharacters… | |
| Aplazada | Media (4.6) | 0.19% | — | LogseqAI | 9/6/2026 | 23/7/2026 | Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to execute arbitrary JavaScript in the… | |
| Aplazada | Media (4.6) | 0.20% | — | LogseqAI | 9/6/2026 | 23/7/2026 | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" without proper sanitization, allowing the execution of arbitrary code in the privileged host context. While only version… | |
| Aplazada | Alta (8.7) | 0.18% | — | LogseqAI | 9/6/2026 | 23/7/2026 | The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript execution in the renderer (e.g. via XSS or a malicious plugin), can read, write, or delete arbitrary files on the user's system. While only… | |
| Aplazada | Alta (7.5) | 0.42% | — | Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI | 1/6/2026 | 22/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a… | |
| Pendiente de análisis | Crítica (9.8) | 0.84% | — | Crowdstrike LogscaleAI | 21/4/2026 | 17/6/2026 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific… | |
| Analizada | Crítica (9.8) | 0.85% | — | Elastic Logstash | 8/4/2026 | 24/7/2026 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker… | |
| Aplazada | Media (4.3) | 0.12% | — | WpblogsynAI | 14/1/2026 | 17/6/2026 | The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's remote sync settings via a forged request granted they can trick a site… | |
| Aplazada | Media (6.4) | 0.22% | — | Divelogs WidgetAI | 12/12/2025 | 17/6/2026 | The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.4) | 0.15% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Analizada | Media (6.9) | 0.26% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | |
| Analizada | Media (6.9) | 0.14% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. | |
| Analizada | Media (5.3) | 0.23% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request. | |
| Analizada | Media (4.8) | 0.17% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page. | |
| Analizada | Media (6.8) | 0.12% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege. | |
| Analizada | Media (6.2) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations. | |
| Analizada | Alta (7.1) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive… | |
| Aplazada | Alta (7.1) | 0.13% | — | Johnh10 Video Blogster LiteAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. |