Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

8594 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.4)——MetformAI7/10/20267/10/2026
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
Pendiente de análisisMedia (5.4)——Redhat Ansible PlatformAI6/10/20266/10/2026
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without…
AplazadaBaja (2.1)——Sourcecodester Performance Indicator SystemAI6/10/20266/10/2026
A vulnerability was detected in SourceCodester Performance Indicator System 1.0. The affected element is an unknown function of the file /opils/admin/view_product.php. Performing a manipulation of the argument Category results in sql injection. Remote exploitation of the attack is possible. The exploit is now public…
Pendiente de análisisCrítica (10)——Payloadcms Plugin Form BuilderAI6/10/20266/10/2026
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
AplazadaMedia (5.1)——Getformwork FormworkAI6/10/20266/10/2026
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be…
AplazadaAlta (7.1)0.19%—Fluentforms Fluent Forms PRO ADD ON PackAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.
AplazadaCrítica (9.3)0.25%—User Subscriptions FormAI6/10/20266/10/2026
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
AplazadaAlta (8.5)0.29%—Buddyboss PlatformAI6/10/20266/10/2026
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
AplazadaAlta (7.1)0.25%—Reputeinfosystems ArformsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
AplazadaAlta (7.1)0.24%—Bestwebsoft Contact Form TO DBAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions.
AplazadaAlta (7.1)0.24%—Rednao Smart FormsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
AplazadaBaja (2.1)0.35%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely.…
AplazadaBaja (2)0.26%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly…
AplazadaAlta (7.1)0.24%—Epiph Form BlockAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
AplazadaMedia (6.9)0.26%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
AplazadaMedia (5.3)0.18%—Wpmanageninja Fluent Forms PROAI5/10/20266/10/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
AplazadaBaja (3.7)0.18%—MetformAI3/10/20266/10/2026
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
AplazadaMedia (5.3)0.21%—MetformAI3/10/20266/10/2026
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.
AplazadaMedia (6.1)0.27%—Calculated Fields FormAI3/10/20266/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to…
AplazadaAlta (7.2)0.32%—Magic Tooltips FOR Contact Form 7AI3/10/20266/10/2026
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
Pendiente de análisisMedia (5.1)0.26%—FormbricksAI3/10/20266/10/2026
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the…
AplazadaAlta (7.1)0.35%—FormworkAI2/10/20265/10/2026
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access…
AplazadaAlta (7.1)0.24%—Meari IOT Cloud PlatformAI2/10/20263/10/2026
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry,…
AplazadaMedia (6.3)0.27%—Meari IOT Cloud PlatformAI2/10/20263/10/2026
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors,…
AplazadaMedia (5.3)0.20%—Softtr Informatics E-commerce PackAI2/10/20266/10/2026
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Orbitaley — Vulnerabilidades