Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.1)0.11%—Wso2 Message BrokerAI2/10/20263/10/2026
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
RecibidaCrítica (9.3)1.4%—Amazon Sagemaker DistributionAI2/10/20262/10/2026
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated…
Pendiente de análisisMedia (6.1)0.15%—Wikimedia MassmessageAI29/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.
AplazadaMedia (6.4)0.19%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.5)0.27%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AplazadaMedia (6.5)0.70%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (5.3)0.56%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check…
AplazadaMedia (6.1)0.23%—Wordplus Better MessagesAI16/9/202618/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Pendiente de análisisMedia (5.4)0.21%—Mediawiki MassmessageAIMediawikiAI14/9/202628/9/2026
An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.
AplazadaCrítica (9)0.27%—Sage AR Automation APIAICash CollectAI9/9/20269/9/2026
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.
AplazadaCrítica (9)0.27%—Sage AR Automation APIAI9/9/20269/9/2026
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier.
AplazadaBaja (2.3)0.66%—Ash-project Usage RulesAI8/9/20268/9/2026
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which…
Pendiente de análisisCrítica (9.8)0.53%—SAP Netweaver Message ServerAI8/9/20269/9/2026
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized…
AplazadaAlta (7.1)0.25%—BP Better MessagesAI3/9/20265/9/2026
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Pendiente de análisisAlta (8.5)0.63%—Amazon Sagemaker Python SDKAI1/9/20263/9/2026
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for…
AplazadaMedia (5.9)1.1%—Sage Employee Self ServiceAI1/9/20269/9/2026
A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended…
AnalizadaMedia (6.5)0.42%—Vmware Spring Advanced Message Queuing Protocol27/8/202631/8/2026
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently…
AnalizadaMedia (6.8)0.27%—Vmware Spring Advanced Message Queuing Protocol27/8/20261/9/2026
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
AnalizadaMedia (4.9)0.45%—Vmware Spring Advanced Message Queuing Protocol27/8/20261/9/2026
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
AnalizadaMedia (6.5)0.32%—Vmware Spring Advanced Message Queuing Protocol27/8/20261/9/2026
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
AnalizadaMedia (6.5)0.42%—Vmware Spring Advanced Message Queuing Protocol27/8/20262/9/2026
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
AplazadaAlta (7.1)0.25%—BP Better MessagesAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
AplazadaBaja (1.9)0.14%—Textplus Text Message AND Call APPAI3/8/202612/8/2026
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly…
AplazadaCrítica (9.8)0.83%—Personal QR MessageAI3/8/202626/8/2026
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
AnalizadaBaja (2.1)0.23%—Msgpack Messagepack30/7/20265/8/2026
MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and…