Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7)0.21%—Newell Brands Dymo IDAI5/10/20266/10/2026
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the…
Pendiente de análisisMedia (5.1)0.15%—Newell Brands Dymo IDAI5/10/20266/10/2026
Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or…
AplazadaMedia (4.3)0.16%—Brandtoss WP Admin AuditAI5/10/20266/10/2026
Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17.
AplazadaAlta (7.1)0.19%—Wpmudev BrandaAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
Pendiente de análisisMedia (6.9)0.53%—Grandstream Gwn7660elrAI18/9/202622/9/2026
Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'. Attackers can query standard MIBs over the…
Pendiente de análisisMedia (5.1)0.18%—Newell Brands Dymo Connect DesktopAI15/9/202622/9/2026
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The fix limits access by file extension…
AplazadaMedia (5.4)0.14%—Themegoods Grand TourAI2/9/20262/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
Pendiente de análisisCrítica (9.2)0.57%—Amazon Strands Agents ToolsAI25/8/202626/8/2026
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument…
Pendiente de análisisAlta (8.6)0.52%—Amazon Strands Agents ToolsAI6/8/202612/8/2026
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace…
Pendiente de análisisAlta (7.5)0.57%—Amazon Strands Agents ToolsAI3/8/20264/8/2026
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue,…
Pendiente de análisisMedia (6.9)0.52%—Strands Agents ToolsAI31/7/20264/8/2026
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to…
AplazadaMedia (6.4)0.33%—Berocket Brands FOR WoocommerceAI24/7/202624/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (4.3)0.27%—Avada Custom BrandingAI23/7/202623/7/2026
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
AplazadaAlta (7.1)0.25%—Grand PhotographyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
AplazadaMedia (4.4)0.31%—Berocket Brands FOR WoocommerceAI23/7/202623/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and…
AplazadaMedia (6.4)0.33%—Berocket Brands FOR WoocommerceAI23/7/202623/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
Pendiente de análisisMedia (6.9)0.42%—Strands Agents ToolsAIElasticsearchAI15/7/202615/7/2026
Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issue in the…
AplazadaCrítica (9.8)0.56%—Themegoods Grand PhotographyAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
AnalizadaMedia (5.4)0.23%—Ijsbrandy Siteimprove Analytics10/7/20266/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1.
AplazadaAlta (7.5)0.51%—Bytes Random Secure TinyAI26/6/20261/7/2026
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are…
AplazadaAlta (7.5)0.51%—Bytes Random SecureAI26/6/20261/7/2026
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in…
AplazadaCrítica (9.8)0.62%💥 PoCWpmudev BrandaAI20/6/202623/6/2026
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's…
AplazadaAlta (7.1)0.18%—Grand CAR RentalAI17/6/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.
AplazadaMedia (6.9)0.39%—BrandfolderAI15/6/202617/6/2026
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to…
AplazadaAlta (8.7)0.54%—HS Brand Logo SliderAI16/5/202617/6/2026
HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions…
Orbitaley — Vulnerabilidades