Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | 0.77% | — | Internlm MindsearchAI | 4/10/2026 | 4/10/2026 | A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Recibida | Media (6.1) | 0.21% | — | Ivorysearch Ivory SearchAI | 3/10/2026 | 3/10/2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.1) | 0.36% | — | 4TU Researchdata DjehutyAI | 1/10/2026 | 2/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:… | |
| Aplazada | Alta (8.4) | 0.30% | — | 4tu.researchdata DjehutyAI | 1/10/2026 | 2/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.… | |
| Pendiente de análisis | Baja (1.2) | 0.30% | — | Wikimedia MediasearchAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Alta (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| En análisis | Media (4.9) | 0.44% | — | ElasticsearchAI | 26/9/2026 | 28/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 1/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Pendiente de análisis | Media (5.5) | 0.27% | — | Wikimedia CirrussearchAI | 24/9/2026 | 24/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0. | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Thebrowser ARC SearchAI | 23/9/2026 | 24/9/2026 | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about… | |
| Aplazada | Alta (8.4) | 0.27% | — | Klever-goAIElasticsearchAI | 23/9/2026 | 24/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Ordasoft Osgallery SearchAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a… | |
| Aplazada | Media (4.3) | 0.23% | — | Search Atlas SEOAI | 19/9/2026 | 21/9/2026 | The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (6.5) | 0.22% | — | JetsearchAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | |
| Aplazada | Alta (8.7) | 0.52% | — | Manticore SearchAI | 16/9/2026 | 22/9/2026 | Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that… | |
| Aplazada | Alta (7.1) | 0.48% | — | Zlt2000 Microservices-platformAIElasticsearchAI | 16/9/2026 | 18/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided… |