Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2786▼ 305 respecto a la semana anterior
Críticas / altas1290▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.40% | — | VictoriametricsAI | 20/8/2026 | 18/9/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageDataPath. An attacker… | |
| Aplazada | Baja (2.9) | 0.75% | — | VictoriametricsAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out… | |
| Analizada | Media (6.8) | 0.46% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this… | |
| Analizada | Alta (7.6) | 0.32% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,… | |
| Analizada | Media (6.8) | 0.39% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 17/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent… | |
| Analizada | Media (6.5) | 0.40% | — | Pevans Metrics\ | 10/6/2026 | 23/6/2026 | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a… | |
| Analizada | Crítica (9.1) | 0.55% | — | Pevans Metrics\ | 10/6/2026 | 24/6/2026 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has… | |
| Analizada | Alta (8.2) | 0.50% | — | Pevans Metrics\ | 10/6/2026 | 24/6/2026 | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and… | |
| Pendiente de análisis | Crítica (9.2) | 0.31% | — | AMD Device Metrics ExporterAI | 15/5/2026 | 17/6/2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability | |
| Aplazada | Media (5.3) | 0.52% | — | ExactmetricsAI | 24/4/2026 | 14/8/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin… | |
| Aplazada | Alta (7.2) | 1.00% | — | ExactmetricsAI | 23/4/2026 | 17/6/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the… | |
| Aplazada | Media (5.4) | 0.28% | — | TextmetricsAI | 13/3/2026 | 17/6/2026 | Vulnerabilidad de autorización faltante en Israpil Textmetrics webtexttool permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Textmetrics: desde n/a hasta <= 3.6.4. | |
| Aplazada | Alta (8.8) | 0.39% | — | ExactmetricsAI | 11/3/2026 | 17/6/2026 | El plugin ExactMetrics – Google Analytics Dashboard para WordPress es vulnerable a la Gestión Inadecuada de Privilegios en las versiones 7.1.0 a la 9.0.2. Esto se debe a que la función 'update_settings()' acepta nombres de configuración de plugin arbitrarios sin una lista blanca de configuraciones permitidas. Esto… | |
| Aplazada | Alta (8.8) | 0.64% | — | ExactmetricsAI | 11/3/2026 | 17/6/2026 | El plugin ExactMetrics – Google Analytics Dashboard para WordPress es vulnerable a Referencia Directa Insegura a Objeto en las versiones 8.6.0 a 9.0.2. Esto se debe a que el método 'store_settings()' en la clase 'ExactMetrics_Onboarding' acepta un parámetro 'triggered_by' proporcionado por el usuario que se utiliza en… | |
| Aplazada | Media (4.3) | 0.24% | — | TextmetricsAI | 23/1/2026 | 17/6/2026 | Neutralización Incorrecta de Etiquetas HTML Relacionadas con Scripts en una Página Web (XSS Básico) en Israpil Textmetrics webtexttool permite la Inyección de Código. Este problema afecta a Textmetrics: desde n/a hasta <= 3.6.3. | |
| Aplazada | Baja (2.7) | 0.34% | — | VictoriametricsAI | 25/11/2025 | 17/6/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits… | |
| Analizada | Crítica (10) | 0.74% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally,… | |
| Analizada | Crítica (10) | 0.77% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and… | |
| Analizada | Crítica (10) | 0.66% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially… | |
| Aplazada | Alta (8.8) | 0.42% | — | SEO MetricsAI | 2/8/2025 | 17/6/2026 | El complemento SEO Metrics para WordPress es vulnerable a la escalada de privilegios debido a la falta de comprobaciones de autorización tanto en el controlador AJAX seo_metrics_handle_connect_button_click() como en la función seo_metrics_handle_custom_endpoint() en las versiones 1.0.5 a 1.0.15. Dado que la acción… | |
| Aplazada | Media (6) | 0.22% | — | Akka-cluster-metricsAI | 28/6/2025 | 17/6/2026 | Desde Akka hasta 2.10.6, akka-cluster-metrics utiliza la serialización de Java para las métricas del clúster. | |
| Modificada | Media (4.8) | 0.23% | — | Textmetrics | 22/4/2025 | 17/6/2026 | La vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') en Israpil Textmetrics permite XSS almacenado. Este problema afecta a Textmetrics desde n/d hasta la versión 3.6.2. | |
| Aplazada | Media (5.4) | 0.53% | — | TextmetricsAI | 27/3/2025 | 17/6/2026 | La vulnerabilidad de falta de autorización en Israpil Textmetrics permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Textmetrics desde n/d hasta la versión 3.6.1. | |
| Aplazada | Media (5.4) | 0.31% | — | Exactmetrics Google Analytics Dashboard FOR WPAI | 24/1/2025 | 17/6/2026 | Vulnerabilidad de falta de autorización en ExactMetrics ExactMetrics permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a ExactMetrics: desde n/a hasta 8.1.0. | |
| Analizada | Alta (7.5) | 0.33% | — | Loway Queuemetrics | 8/9/2024 | 17/6/2026 | Loway - CWE-204: Discrepancia de respuesta observable |