Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

751 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.37%—Wpspellcheck WP Spell CheckAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
AplazadaAlta (7.5)0.25%—Tipsandtricks-hq WP Express CheckoutAI30/9/202630/9/2026
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
AnalizadaCrítica (9.8)20%⚠ Explotación activa💥 PoCCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/9/202623/9/2026
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
AplazadaMedia (5.3)0.35%—CheckmkAI22/9/20265/10/2026
Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p38, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords…
AplazadaMedia (5.3)0.42%—CheckmkAI22/9/202622/9/2026
Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their…
AplazadaMedia (5.3)0.38%—CheckmkAI21/9/202621/9/2026
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Pendiente de análisisAlta (8)0.41%—Jenkins Owasp Dependency-checkAIJenkinsAI16/9/202618/9/2026
Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
AplazadaAlta (8.2)0.71%—Stripe CheckoutAI14/9/202618/9/2026
Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows a remote, unauthenticated attacker holding a valid Stripe…
Pendiente de análisisAlta (7.7)0.53%—Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI14/9/202630/9/2026
LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively…
Pendiente de análisisBaja (3.1)0.24%—Mediawiki CheckuserAIMediawikiAI14/9/202616/9/2026
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
AplazadaCrítica (9.8)1.1%—Mipl Grouped Checkout Fields FOR WoocommerceAI11/9/202611/9/2026
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated…
Pendiente de análisisBaja (2.4)0.19%💥 PoCPaloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
Pendiente de análisisBaja (1.1)0.82%—Paloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
AplazadaMedia (5.5)0.10%—Thesycon DPC Latency CheckerAI9/9/20269/9/2026
A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that accepts user-controlled input without validating pointers before passing them to…
Pendiente de análisisCrítica (9.8)3.7%—Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI9/9/202610/9/2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
AnalizadaCrítica (9.8)7.5%⚠ Explotación activa💥 PoCCheckpoint Gaia EmbeddedCheckpoint Gaia OS9/9/202623/9/2026
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
AplazadaMedia (5.3)0.16%—Tipsandtricks-hq WP Express CheckoutAI9/9/20269/9/2026
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
AplazadaMedia (4.3)0.43%—Checkout Custom Fields Builder FOR WoocommerceAI9/9/20269/9/2026
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.14%—CheckmkAI4/9/20268/9/2026
Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate.
AplazadaAlta (8.2)0.47%—WhmcsAI2checkoutAI4/9/202614/9/2026
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific…
AplazadaAlta (7.1)0.49%—Bluewavelabs CheckmateAI3/9/202610/9/2026
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and…
AplazadaMedia (5.3)0.16%—Tipsandtricks-hq WP Express CheckoutAI2/9/20263/9/2026
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
AplazadaMedia (5.5)0.26%—Broken Link CheckerAI2/9/20263/9/2026
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
Orbitaley — Vulnerabilidades