Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2807▲ 74 respecto a la semana anterior
Críticas / altas1475▲ 313 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
411 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | |
| Aplazada | Alta (8.1) | 0.21% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to… | |
| Aplazada | Baja (3.3) | 0.13% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting… | |
| Aplazada | Alta (8.7) | 0.51% | — | Llama FactoryAI | 4/9/2026 | 24/9/2026 | LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and re-resolves DNS without re-validation,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Webfactoryltd Under ConstructionAI | 3/9/2026 | 7/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Rockwellautomation Factorytalk Activation ManagerAI | 1/9/2026 | 1/9/2026 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack… | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. | |
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa | Jfrog Artifactory | 28/8/2026 | 3/9/2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Jfrog ArtifactoryAI | 25/8/2026 | 28/8/2026 | An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions. | |
| Pendiente de análisis | Baja (3.5) | 0.29% | — | Jfrog ArtifactoryAICocoapodsAI | 25/8/2026 | 28/8/2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (10) | 0.52% | — | Link FactoryAI | 13/8/2026 | 26/8/2026 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check). | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Analizada | Alta (8.8) | 0.52% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |
| Analizada | Alta (7.5) | 9.8% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 1/10/2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | |
| Analizada | Media (4.3) | 0.28% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An authenticated user without repository read permission may access package metadata under specific conditions. | |
| Analizada | Media (5.9) | 0.41% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. | |
| Analizada | Alta (8.1) | 0.20% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | |
| Analizada | Alta (7.2) | 0.33% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A holder of a valid integration credential may impersonate other users under specific conditions. | |
| Analizada | Media (6.5) | 0.35% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | A low-privileged authenticated user may access restricted support information under specific conditions. | |
| Analizada | Media (5.3) | 0.66% | ⚠ Explotación activa | Jfrog Artifactory | 12/8/2026 | 28/8/2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| Analizada | Media (6.7) | 0.12% | — | Jfrog Artifactory | 12/8/2026 | 11/9/2026 | Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users. | |
| Analizada | Media (5.3) | 0.46% | — | Jfrog Artifactory | 12/8/2026 | 2/9/2026 | An unauthenticated user may bypass authentication under specific cache conditions. |