Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.41% | — | Apache KafkaAIStreamshub Console FOR Apache KafkaAI | 28/9/2026 | 5/10/2026 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to… | |
| Aplazada | Baja (1.9) | 0.17% | — | Incomestreamsurfer ROO Code Memory Bank MCP ServerAI | 9/8/2026 | 14/8/2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation… | |
| Aplazada | Alta (7.1) | 0.24% | — | Streamsoft Business IntelligenceAI | 29/7/2026 | 30/7/2026 | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login. | |
| Aplazada | Media (6.3) | 0.25% | — | Streamsoft PrestizAI | 12/3/2026 | 17/6/2026 | Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92. | |
| Aplazada | Media (4.3) | 0.12% | — | Channelize Live Shopping Video StreamsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | Social StreamsAI | 23/7/2025 | 17/6/2026 | The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their user meta information in the update_user_meta() function. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat Event Driven AnsibleAIRedhat Event StreamsAI | 28/3/2025 | 17/6/2026 | A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams. | |
| Aplazada | Alta (8.2) | 0.40% | — | Streamsoft PrestizAI | 28/3/2025 | 17/6/2026 | Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed. This issue was… | |
| Aplazada | Alta (8.6) | 0.44% | — | Streamsoft PrestizAI | 28/3/2025 | 17/6/2026 | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. This issue was fixed in 18.1.376.37 version of the software. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hoststreamsell HSS Embed Streaming VideoAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoststreamsell HSS Embed Streaming Video hss-embed-streaming-video allows Reflected XSS.This issue affects HSS Embed Streaming Video: from n/a through <= 3.23. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.5) | 0.44% | — | Squareup OkhttpRedhat A-mq Streams | 27/9/2023 | 23/6/2026 | A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions. | |
| Modificada | Media (6.7) | 0.33% | — | Redhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+5 | 24/8/2022 | 17/6/2026 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML. | |
| Modificada | Alta (7.2) | 0.47% | — | IBM Event Streams | 12/7/2021 | 17/6/2026 | IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and deploy them in the cluster and gain privileges of another user. IBM X-Force ID: 203450. | |
| Modificada | Crítica (9.8) | 2.1% | — | Appbase Streams | 16/12/2020 | 17/6/2026 | The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Alta (8.8) | 1.3% | — | IBM Event Streams | 14/8/2020 | 17/6/2026 | IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233. | |
| Modificada | Media (5.9) | 0.87% | — | IBM Infosphere Streams | 21/3/2019 | 17/6/2026 | IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632. | |
| Modificada | Media (5.3) | 1.7% | — | IBM Event Streams | 18/12/2018 | 17/6/2026 | IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507. | |
| Modificada | Media (5.4) | 0.66% | — | Atlassian Activity Streams | 29/1/2018 | 17/6/2026 | Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive… | |
| Modificada | Media (5.4) | 0.93% | — | IBM Infosphere Streams | 10/8/2017 | 17/6/2026 | IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127632. | |
| Modificada | Alta (7) | 0.26% | — | IBM Infosphere StreamsIBM Streams | 2/7/2016 | 17/6/2026 | IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 1.7% | — | Simpestreams Project SimplestreamsCanonical Ubuntu Linux | 9/10/2015 | 17/6/2026 | Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response. |