Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
–

1096 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)——Redux FrameworkAI1/10/20261/10/2026
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (4.3)——Redux FrameworkAI1/10/20261/10/2026
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (6.3)0.32%—Circl AIL FrameworkAI25/9/202625/9/2026
The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file paths—was interpolated directly into inline JavaScript contexts within the HTML…
AplazadaMedia (6.9)0.43%—Circl AIL FrameworkAI25/9/202625/9/2026
The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), without performing proper hostname parsing or onion-domain validation. An…
AplazadaMedia (6.3)0.34%—Circl AIL FrameworkAI25/9/202625/9/2026
The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified that the cookiejar existed and, if its access level was 0, compared the cookiejar's…
AplazadaAlta (8.5)0.35%—Circl AIL FrameworkAI25/9/202625/9/2026
The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the username timeline, the application renders these stored usernames into the DOM using D3's…
AplazadaMedia (5.1)0.40%—Circl AIL FrameworkAI25/9/202625/9/2026
The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g., <img src=x onerror=alert(1)> or <svg onload=...>) in the tag name. When another…
AplazadaAlta (8.5)0.27%—Circl AIL FrameworkAI25/9/202625/9/2026
The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message.html and var/www/templates/objects/item/show_item.html. In both templates,…
AplazadaAlta (8.6)0.44%—Uvdesk Core-frameworkAI21/9/202622/9/2026
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full…
AplazadaMedia (5.3)0.30%—Uvdesk Core-frameworkAI21/9/202622/9/2026
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not…
AplazadaMedia (5.1)0.18%—Uvdesk Core-frameworkAISwiftmailerAI21/9/202624/9/2026
UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members…
AplazadaMedia (6.4)0.38%—Redux FrameworkAI19/9/202621/9/2026
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_save() function scalar values bypass the sanitization logic that only processes…
AplazadaMedia (6.4)0.42%—Redux FrameworkAI19/9/202621/9/2026
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 This is due to insufficient input sanitization of nested array values in the user_meta_save() function and unsafe output of filter CSS values in the render()…
Pendiente de análisisMedia (5.4)0.44%—Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI18/9/202621/9/2026
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,…
AnalizadaMedia (5.7)0.15%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
AnalizadaMedia (6.8)0.07%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
AnalizadaMedia (6.8)0.07%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
AnalizadaAlta (8.8)0.41%—Dell Update Package Framework16/9/202621/9/2026
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (6)0.15%—Dell Update Package Framework16/9/202621/9/2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaMedia (6)0.15%—Dell Update Package Framework16/9/202621/9/2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaAlta (7.8)0.15%—Dell Update Package Framework16/9/202621/9/2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.8)0.59%—Dell Update Package Framework16/9/202621/9/2026
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Pendiente de análisisAlta (8.8)0.83%—Jenkins Robot Framework PluginAI16/9/202618/9/2026
Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file…
AplazadaAlta (7.1)0.29%—Oracle Applications FrameworkAI15/9/202621/9/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Applications FrameworkAI15/9/202617/9/2026
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.…