Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

509 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.13%—Virtue Ascend Pinnacle ToolkitAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
Pendiente de análisisCrítica (9.4)0.61%—WP ToolkitAICpanelAI23/9/202624/9/2026
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Pendiente de análisisAlta (8.7)0.67%—Plesk RubyAIPlesk Node.js ToolkitAI14/9/202618/9/2026
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
AplazadaAlta (8.7)0.48%—OWL DocumentprocessingtoolkitAI4/9/202624/9/2026
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses…
AnalizadaAlta (8.1)0.35%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is…
AnalizadaMedia (4.3)0.25%—Splunk AI Toolkit19/8/202624/8/2026
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history…
AnalizadaAlta (8.1)0.35%—Splunk AI Toolkit19/8/202621/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes…
AnalizadaAlta (7.5)0.32%—Splunk AI Toolkit19/8/202621/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as…
AnalizadaAlta (8.8)0.65%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix…
AnalizadaAlta (8.3)0.35%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because…
AnalizadaMedia (5.9)0.18%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk…
AnalizadaMedia (5.4)0.23%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container…
En análisisAlta (8.3)0.47%—Splunk AI Toolkit19/8/202626/8/2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege…
Pendiente de análisisAlta (7.6)0.48%—Gbif Integrated Publishing ToolkitAI18/8/202631/8/2026
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection
Pendiente de análisisCrítica (9.1)0.86%—Gbif Integrated Publishing ToolkitAI18/8/202631/8/2026
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
Pendiente de análisisCrítica (9.2)0.86%—Gbif Integrated Publishing ToolkitAI18/8/202631/8/2026
Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass
AplazadaMedia (4.9)0.44%—Servit Affiliate-toolkitAI14/8/202614/8/2026
The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaAlta (8.1)0.38%—Travelfic ToolkitAI13/8/202614/8/2026
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
En análisisMedia (5.4)0.16%—Cluster Management Toolkit FOR KubernetesAI11/8/202612/8/2026
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result…
AplazadaAlta (7.2)0.50%—Everest ToolkitAI1/8/202626/8/2026
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to…
AplazadaMedia (6.5)0.22%—Virtue ToolkitAIAscend ToolkitAIPinnacle ToolkitAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
AplazadaCrítica (9.1)0.86%—Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI21/7/202623/7/2026
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In…
AplazadaMedia (5.3)0.37%—Django-oauth-toolkitAI19/7/202620/7/2026
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project was informed of the problem early…
AplazadaAlta (8.8)1.00%—Swiss Toolkit FOR WPAI11/7/202613/7/2026
The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and…
AplazadaMedia (6.4)0.35%—Affiliate-toolkit WP Affiliate Plugin With Amazon PluginAI10/7/202614/7/2026
The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…