Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Wpspellcheck WP Spell CheckAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1. | |
| Aplazada | Alta (7.5) | 0.25% | — | Tipsandtricks-hq WP Express CheckoutAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Aplazada | Media (5.3) | 0.35% | — | CheckmkAI | 22/9/2026 | 5/10/2026 | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p38, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords… | |
| Aplazada | Media (5.3) | 0.42% | — | CheckmkAI | 22/9/2026 | 22/9/2026 | Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their… | |
| Aplazada | Media (5.3) | 0.38% | — | CheckmkAI | 21/9/2026 | 21/9/2026 | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins Owasp Dependency-checkAIJenkinsAI | 16/9/2026 | 18/9/2026 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Aplazada | Alta (8.2) | 0.71% | — | Stripe CheckoutAI | 14/9/2026 | 18/9/2026 | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows a remote, unauthenticated attacker holding a valid Stripe… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI | 14/9/2026 | 30/9/2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki CheckuserAIMediawikiAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mipl Grouped Checkout Fields FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated… | |
| Pendiente de análisis | Baja (2.4) | 0.19% | 💥 PoC | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. | |
| Pendiente de análisis | Baja (1.1) | 0.82% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. | |
| Aplazada | Media (5.5) | 0.10% | — | Thesycon DPC Latency CheckerAI | 9/9/2026 | 9/9/2026 | A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that accepts user-controlled input without validating pointers before passing them to… | |
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Analizada | Crítica (9.8) | 7.5% | ⚠ Explotación activa💥 PoC | Checkpoint Gaia EmbeddedCheckpoint Gaia OS | 9/9/2026 | 23/9/2026 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 9/9/2026 | 9/9/2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Media (4.3) | 0.43% | — | Checkout Custom Fields Builder FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.14% | — | CheckmkAI | 4/9/2026 | 8/9/2026 | Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was issued by their own root certificate. | |
| Aplazada | Alta (8.2) | 0.47% | — | WhmcsAI2checkoutAI | 4/9/2026 | 14/9/2026 | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific… | |
| Aplazada | Alta (7.1) | 0.49% | — | Bluewavelabs CheckmateAI | 3/9/2026 | 10/9/2026 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and… | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 2/9/2026 | 3/9/2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Media (5.5) | 0.26% | — | Broken Link CheckerAI | 2/9/2026 | 3/9/2026 | Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. |