Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
1832 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6) | — | — | Amazon Powertools FOR AWS Lambda PythonAI | 1/10/2026 | 1/10/2026 | A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0. | |
| Recibida | Alta (7.4) | — | — | Graphql ToolsAI | 1/10/2026 | 1/10/2026 | GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with… | |
| Aplazada | Alta (8.8) | — | — | Bytecore MCP Connector FOR AI ToolsAI | 1/10/2026 | 1/10/2026 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| Aplazada | Alta (8.8) | — | — | Bytecore Stack MCP Connector FOR AI ToolsAI | 1/10/2026 | 1/10/2026 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be… | |
| Aplazada | Baja (2.1) | — | — | Formtools Form ToolsAI | 1/10/2026 | 1/10/2026 | A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of… | |
| Aplazada | Alta (7.2) | 0.54% | — | Wptools Extra Product OptionsAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Stifli Backup ToolsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | |
| Pendiente de análisis | Alta (8.2) | 0.20% | — | Networkupstools Network UPS ToolsAI | 28/9/2026 | 30/9/2026 | Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms… | |
| Pendiente de análisis | Alta (7.5) | 0.52% | — | Psd-toolsAI | 22/9/2026 | 23/9/2026 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Cowork Bench Pdf-tools-mcpAI | 20/9/2026 | 21/9/2026 | A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path… | |
| Aplazada | Baja (2.1) | 0.41% | — | Grimmory-tools GrimmoryAI | 19/9/2026 | 21/9/2026 | A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in… | |
| Aplazada | Baja (2.1) | 0.39% | — | Grimmory-tools GrimmoryAI | 19/9/2026 | 22/9/2026 | A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect… | |
| Pendiente de análisis | Alta (7.7) | 0.30% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Fusion MiddlewareAIOracle Middleware Common Libraries AND ToolsAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the… | |
| Pendiente de análisis | Alta (8.5) | 0.29% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Pendiente de análisis | Alta (7.3) | 0.32% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Peoplesoft Enterprise PeopletoolsAI | 15/9/2026 | 16/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (8.1) | 0.42% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (7.2) | 0.14% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise… | |
| Analizada | Alta (7) | 0.13% | — | Oracle Peoplesoft Enterprise Peopletools | 15/9/2026 | 21/9/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to… |