Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.10% | — | Google GvisorAI | 25/9/2026 | 25/9/2026 | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character… | |
| Aplazada | Media (5.5) | 0.50% | — | Dromara Orion-visorAI | 13/9/2026 | 14/9/2026 | A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The… | |
| Aplazada | Media (5.5) | 0.50% | — | Dromara Orion-visorAI | 13/9/2026 | 19/9/2026 | A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public… | |
| Aplazada | Media (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 5/8/2026 | 12/8/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle JD Edwards Enterpriseone Solution Advisor | 21/7/2026 | 6/8/2026 | Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor.… | |
| Aplazada | Media (4.9) | 0.48% | — | Ljapps WP Tripadvisor Review SliderAI | 16/7/2026 | 16/7/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.33% | — | Reviews Widgets FOR Google Yelp AND TripadvisorAI | 6/7/2026 | 7/7/2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()… | |
| Aplazada | Alta (8.5) | 0.18% | — | Network Inventory AdvisorAI | 19/6/2026 | 29/9/2026 | Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with… | |
| Aplazada | Alta (8.9) | 0.18% | — | Cloudhypervisor Cloud HypervisorAI | 10/6/2026 | 23/7/2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the same head_index while asynchronous block I/O is enabled (e.g. io_uring, aio).… | |
| Analizada | Media (5.3) | 0.24% | — | Netapp Active IQ Config Advisor | 3/6/2026 | 22/7/2026 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Aplazada | Media (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 26/5/2026 | 24/7/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Home-assistant Home AssistantAIHome-assistant SupervisorAI | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict… | |
| Aplazada | Media (6.5) | 0.22% | — | Ljapps WP Tripadvisor Review SliderAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue affects WP TripAdvisor Review Slider: from n/a through <= 14.1. | |
| Analizada | Media (6.1) | 0.16% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 25/3/2026 | 12/8/2026 | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Analizada | Crítica (9.1) | 0.60% | — | Cloudhypervisor Cloud Hypervisor | 21/2/2026 | 17/6/2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A malicious guest can overwrite its disk header with a crafted QCOW2 structure… | |
| Analizada | Media (6) | 0.17% | — | IBM Powervm Hypervisor | 2/2/2026 | 17/6/2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures. | |
| Analizada | Baja (3.3) | 0.13% | — | IBM Powervm Hypervisor | 2/2/2026 | 17/6/2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations. | |
| Analizada | Media (6.5) | 0.32% | — | Dell Data Protection Advisor | 23/1/2026 | 17/6/2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR Objectscale*Progress ECS Connection ManagerProgress LoadmasterProgress Moveit WAF+1 | 13/1/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Aplazada | Alta (7.1) | 0.22% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Alta (8.2) | 0.20% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Media (4.3) | 0.20% | — | SupervisorAI | 24/10/2025 | 17/6/2026 | The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX functions in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update various plugin settings. | |
| Aplazada | Media (5.5) | 0.15% | — | BitvisorAI | 16/10/2025 | 17/6/2026 | A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. |