Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.58%—Temporal-serverAI21/9/202622/9/2026
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are…
Pendiente de análisisAlta (7.2)0.78%—Temporal ServerAI21/9/202622/9/2026
Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL host matched the configured callback address allowlist, whose URL path was any…
Pendiente de análisisAlta (8.7)0.58%—Temporalio Ringpop-goAI21/9/202622/9/2026
github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network peer that can reach a live Ringpop TChannel listener can repeatedly submit changes…
Pendiente de análisisAlta (8.7)0.71%—Temporalio Tchannel-goAI21/9/202622/9/2026
github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can supply such a malformed call fragment, including as a…
Pendiente de análisisAlta (8.7)0.71%—Temporalio Tchannel-goAI21/9/202622/9/2026
github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksum type. The parser uses that value as an index into a…
Pendiente de análisisAlta (8.7)0.67%—Temporalio SqlparserAITemporalAI21/9/202622/9/2026
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively traverse that tree. An application that parses attacker-controlled SQL and later…
Pendiente de análisisAlta (7.1)0.27%—TemporalAI21/9/202622/9/2026
Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every candidate time, causing the server to evaluate…
Pendiente de análisisAlta (8.7)0.39%—Temporalio SqlparserAITemporalAI21/9/202622/9/2026
temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc before using it as a slice boundary. The resulting Go runtime…
AplazadaMedia (5.5)0.32%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC…
AplazadaAlta (7.2)0.46%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing…
AplazadaBaja (2.3)0.37%—Temporal UI ServerAI11/8/20268/9/2026
When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and…
Pendiente de análisisMedia (6.5)0.35%—Tempo OperatorAI13/7/202613/7/2026
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
AnalizadaMedia (6.5)0.41%—Grafana Tempo19/6/202629/6/2026
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.
AplazadaCrítica (9.8)2.9%—Temporary LoginAI1/5/202617/6/2026
The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to verify that the 'temp-login-token' GET parameter is a scalar string before processing it. When the…
ModificadaAlta (7.5)0.64%—Grafana Tempo24/4/20269/9/2026
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
Pendiente de análisisMedia (6.3)0.66%—TemporalAI10/4/20268/7/2026
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests without credentials.…
Pendiente de análisisCrítica (9.3)0.44%—Contemporary Controls Basc 20TAI9/4/202630/9/2026
An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.
Pendiente de análisisBaja (2.3)0.30%—Temporal ServerAI1/4/202617/6/2026
A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names. This was due to a bug introduced in…
AnalizadaAlta (7.5)0.16%—Grafana Tempo26/3/202617/6/2026
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.
AplazadaMedia (6.1)0.24%—Tempo WorklogproAIAtlassian JiraAI20/1/202617/6/2026
The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 allows attackers to inject arbitrary HTML or JavaScript via XSS. This is exploited via a crafted payload placed in the name of a filter. This code is executed in the browser when the user attempts to…
AplazadaMedia (5.3)0.40%—TemporalAI30/12/202517/6/2026
When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a different namespace than the namespace authorized at the gRPC boundary.…
AplazadaBaja (1.3)0.43%—TemporalAI30/12/202517/6/2026
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace…
AplazadaMedia (6.9)0.39%—TemporalAI15/9/202517/6/2026
Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and…
AplazadaMedia (6.4)0.23%—Temporarily Hidden ContentAI19/7/202517/6/2026
The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temphc-start' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.3)0.38%—Contempoinc Real EstateAI19/5/202517/6/2026
Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2.