Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

1832 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6)——Amazon Powertools FOR AWS Lambda PythonAI1/10/20261/10/2026
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
RecibidaAlta (7.4)——Graphql ToolsAI1/10/20261/10/2026
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with…
AplazadaAlta (8.8)——Bytecore MCP Connector FOR AI ToolsAI1/10/20261/10/2026
Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.
AplazadaAlta (8.8)——Bytecore Stack MCP Connector FOR AI ToolsAI1/10/20261/10/2026
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's…
AplazadaBaja (2.1)——Formtools Form ToolsAI1/10/20261/10/2026
A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may…
AplazadaBaja (2.1)——Formtools Form ToolsAI1/10/20261/10/2026
A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be…
AplazadaBaja (2.1)——Formtools Form ToolsAI1/10/20261/10/2026
A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of…
AplazadaAlta (7.2)0.54%—Wptools Extra Product OptionsAI30/9/202630/9/2026
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
AplazadaAlta (7.5)0.42%—Stifli Backup ToolsAI30/9/202630/9/2026
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
Pendiente de análisisAlta (8.2)0.20%—Networkupstools Network UPS ToolsAI28/9/202630/9/2026
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms…
Pendiente de análisisAlta (7.5)0.52%—Psd-toolsAI22/9/202623/9/2026
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the…
AplazadaBaja (2.1)0.37%—Cowork Bench Pdf-tools-mcpAI20/9/202621/9/2026
A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path…
AplazadaBaja (2.1)0.41%—Grimmory-tools GrimmoryAI19/9/202621/9/2026
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in…
AplazadaBaja (2.1)0.39%—Grimmory-tools GrimmoryAI19/9/202622/9/2026
A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect…
Pendiente de análisisAlta (7.7)0.30%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202617/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While…
AplazadaAlta (7.8)0.14%—Oracle Fusion MiddlewareAIOracle Middleware Common Libraries AND ToolsAI15/9/202617/9/2026
Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the…
Pendiente de análisisAlta (8.5)0.29%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202616/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While…
Pendiente de análisisAlta (7.5)0.46%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202616/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful…
Pendiente de análisisAlta (7.3)0.32%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202616/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…
Pendiente de análisisAlta (8.1)0.37%—Oracle Peoplesoft Enterprise PeopletoolsAI15/9/202616/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
AnalizadaAlta (8.1)0.42%—Oracle Peoplesoft Enterprise Peopletools15/9/202621/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of…
AnalizadaAlta (7.8)0.16%—Oracle Peoplesoft Enterprise Peopletools15/9/202621/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise…
AnalizadaAlta (8.8)0.43%—Oracle Peoplesoft Enterprise Peopletools15/9/202621/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
AnalizadaAlta (7.2)0.14%—Oracle Peoplesoft Enterprise Peopletools15/9/202621/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise…
AnalizadaAlta (7)0.13%—Oracle Peoplesoft Enterprise Peopletools15/9/202621/9/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to…