Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Crítica (9.1) | 1.0% | — | HOT ChocolateAI | 18/4/2026 | 17/6/2026 | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a… | |
| Analizada | Crítica (9.8) | 0.33% | — | Frentix Openolat | 30/3/2026 | 17/6/2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards the signature segment of… | |
| Analizada | Alta (8.8) | 0.53% | — | Frentix Openolat | 30/3/2026 | 17/6/2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author role can inject Velocity directives into a reminder email template. When the reminder is processed (either triggered… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpradiant Chocolate HouseAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chocolate House: from n/a through <= 1.1.5. | |
| Analizada | Crítica (9.1) | 0.39% | — | Fortinet Fortiisolator | 14/10/2025 | 17/6/2026 | An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via… | |
| Analizada | Media (4.3) | 0.33% | — | Fortinet Fortiisolator | 18/7/2025 | 17/6/2026 | An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request. | |
| Analizada | Media (6.7) | 0.47% | — | Fortinet FortiisolatorFortinet Fortisandbox | 18/7/2025 | 17/6/2026 | An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a… | |
| Analizada | Media (6.7) | 0.45% | — | Fortinet Fortiisolator | 8/4/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests. | |
| Analizada | Alta (7.2) | 1.2% | — | Fortinet Fortiisolator | 8/4/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged attacker with super-admin profile and CLI access to execute unauthorized code via specifically crafted HTTP requests. | |
| Analizada | Alta (8.8) | 1.0% | — | Fortinet Fortiisolator | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically… | |
| Aplazada | Alta (7.5) | 0.47% | — | LTL Freight Quotes Purolator EditionAI | 22/2/2025 | 17/6/2026 | The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (7.1) | 0.24% | — | Robert Kolatzek WP DoodlezAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robert_kolatzek WP doodlez wpdoodlez allows Stored XSS.This issue affects WP doodlez: from n/a through <= 1.0.10. | |
| Analizada | Alta (7.5) | 0.43% | — | Frentix Openolat | 11/3/2024 | 17/6/2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configured system user and SSRF. The problem is fixed in version 18.1.6 and 18.2.2. It… | |
| Analizada | Media (5.4) | 0.55% | — | Frentix Openolat | 20/2/2024 | 17/6/2026 | The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of OpenOlat version 18.1.5 (or lower) as an authenticated user without any other rights. Although the filetypes are limited, an SVG image containing an XSS payload can… | |
| Modificada | Media (5.4) | 0.56% | — | Frentix Openolat | 20/2/2024 | 17/6/2026 | The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter… | |
| Modificada | Alta (7.8) | 0.46% | — | Fortinet Fortiisolator | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version… | |
| Modificada | Media (6.5) | 0.64% | — | Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines | 26/7/2023 | 17/6/2026 | The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials… | |
| Modificada | Alta (7.8) | 0.17% | — | Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8) | 0.35% | — | WUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx FirmwareWUT Com-server Highspeed 100baselx Firmware+12 | 13/12/2022 | 17/6/2026 | Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP… | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey PHP | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder. | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Azure-pipelines-agent | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder. | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Python3 | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder. | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Cmder | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder. | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Ruby | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder. |