Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.13% | — | JDX MiseAI | 18/8/2026 | 18/9/2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a root-installed… | |
| Aplazada | Media (6.5) | 0.27% | — | Internal Link OptimiserAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Lumise Product Designer FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before… | |
| Aplazada | Baja (2.1) | 0.45% | — | Spencermountain CompromiseAI | 14/7/2026 | 14/7/2026 | A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the argument plugin leads to improperly controlled modification of object prototype attributes. Remote exploitation of the… | |
| Aplazada | Media (6.3) | 0.16% | — | JDX MiseAI | 26/6/2026 | 27/6/2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token. An attacker who can place a .mise.toml in a repository can execute… | |
| Aplazada | Alta (8.6) | 0.18% | — | JDX MiseAI | 26/6/2026 | 26/6/2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are loaded on a path that never reaches it. When a directory has a task-include dir (mise-tasks/, .mise/tasks/, …) but no… | |
| Aplazada | Media (5.5) | 0.17% | — | JDX MiseAI | 26/6/2026 | 26/6/2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's symlink path uses the raw… | |
| Aplazada | Crítica (9.6) | 0.69% | — | JDX MiseAI | 26/6/2026 | 29/6/2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not subject to trust… | |
| Aplazada | Alta (8.7) | 0.31% | — | Heatmiser Wifi ThermostatAI | 29/5/2026 | 21/7/2026 | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields… | |
| Pendiente de análisis | Media (6.3) | 0.34% | — | Teamviewer DEX Platform On-premisesAI | 13/5/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution… | |
| Analizada | Media (5.3) | 0.13% | — | Heatmiser Wifi Thermostat | 12/4/2026 | 17/6/2026 | Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to… | |
| Analizada | Alta (7.8) | 0.13% | — | JDX Mise | 7/4/2026 | 24/7/2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach… | |
| Aplazada | Crítica (9.3) | 0.28% | — | King-theme Lumise Product DesignerAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9. | |
| Aplazada | Media (5.1) | 0.23% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields. | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.8) | 0.33% | — | Therefore Corporation Gmbh Therefore OnlineAITherefore Corporation Gmbh Therefore On-premisesAI | 31/10/2025 | 17/6/2026 | Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore™ Server. If… | |
| Aplazada | Media (6.8) | 0.28% | — | Okta On-premises ProvisioningAI | 22/7/2025 | 17/6/2026 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by… | |
| Analizada | Media (5.4) | 0.22% | — | Vitaly-t Pg-promise | 12/6/2025 | 17/6/2026 | pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers. | |
| Aplazada | Alta (8.3) | 0.47% | — | SAP S/4hana Cloud Private EditionAISAP S/4hana ON PremiseAI | 13/5/2025 | 17/6/2026 | SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs. This is due to lack of input validation and no authorization… | |
| Aplazada | Alta (7.1) | 0.19% | — | Toast Plugins Internal Link OptimiserAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Stored XSS.This issue affects Internal Link Optimiser: from n/a through <= 5.1.3. | |
| Aplazada | Media (6.5) | 0.31% | — | Toast Plugins Internal Link OptimiserAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Link Optimiser: from n/a through <= 5.1.2. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Menlo On-premise ApplianceAI | 14/12/2024 | 17/6/2026 | In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+. | |
| Aplazada | Media (6.5) | 0.48% | — | Zohocorp Manageengine Analytics PlusAIZoho Analytics On-premiseAI | 3/10/2024 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. |