Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8594 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.4) | — | — | MetformAI | 7/10/2026 | 7/10/2026 | The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | |
| Pendiente de análisis | Media (5.4) | — | — | Redhat Ansible PlatformAI | 6/10/2026 | 6/10/2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without… | |
| Aplazada | Baja (2.1) | — | — | Sourcecodester Performance Indicator SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected element is an unknown function of the file /opils/admin/view_product.php. Performing a manipulation of the argument Category results in sql injection. Remote exploitation of the attack is possible. The exploit is now public… | |
| Pendiente de análisis | Crítica (10) | — | — | Payloadcms Plugin Form BuilderAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | |
| Aplazada | Media (5.1) | — | — | Getformwork FormworkAI | 6/10/2026 | 6/10/2026 | A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be… | |
| Aplazada | Alta (7.1) | 0.19% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | |
| Aplazada | Crítica (9.3) | 0.25% | — | User Subscriptions FormAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | |
| Aplazada | Alta (8.5) | 0.29% | — | Buddyboss PlatformAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Reputeinfosystems ArformsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bestwebsoft Contact Form TO DBAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Rednao Smart FormsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions. | |
| Aplazada | Baja (2.1) | 0.35% | — | Sourcecodester Simple Student Information SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely.… | |
| Aplazada | Baja (2) | 0.26% | — | Sourcecodester Simple Student Information SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (7.1) | 0.24% | — | Epiph Form BlockAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. | |
| Aplazada | Media (6.9) | 0.26% | — | Sourcecodester Simple Student Information SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely. | |
| Aplazada | Media (5.3) | 0.18% | — | Wpmanageninja Fluent Forms PROAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | |
| Aplazada | Baja (3.7) | 0.18% | — | MetformAI | 3/10/2026 | 6/10/2026 | The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies. | |
| Aplazada | Media (5.3) | 0.21% | — | MetformAI | 3/10/2026 | 6/10/2026 | The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API. | |
| Aplazada | Media (6.1) | 0.27% | — | Calculated Fields FormAI | 3/10/2026 | 6/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to… | |
| Aplazada | Alta (7.2) | 0.32% | — | Magic Tooltips FOR Contact Form 7AI | 3/10/2026 | 6/10/2026 | The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Media (5.1) | 0.26% | — | FormbricksAI | 3/10/2026 | 6/10/2026 | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the… | |
| Aplazada | Alta (7.1) | 0.35% | — | FormworkAI | 2/10/2026 | 5/10/2026 | Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access… | |
| Aplazada | Alta (7.1) | 0.24% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry,… | |
| Aplazada | Media (6.3) | 0.27% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors,… | |
| Aplazada | Media (5.3) | 0.20% | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 6/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |