Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.09% | — | Freshlightlab WP Mobile MenuAI | 30/9/2026 | 30/9/2026 | The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia Mediawiki Refreshed SkinAI | 29/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Alta (8.7) | 0.46% | — | MetasfreshAI | 16/9/2026 | 23/9/2026 | metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access. | |
| Analizada | Alta (8.6) | 0.29% | — | Octopus Codefresh | 25/8/2026 | 28/9/2026 | In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. | |
| Aplazada | Alta (7.4) | 0.79% | — | FreshtomatoAIUcdok TomatoAI | 13/7/2026 | 15/7/2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is… | |
| Aplazada | Baja (2.1) | 1.8% | — | FreshtomatoAIUcdok TomatoAI | 13/7/2026 | 13/7/2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (6.4) | 0.33% | — | Fresh PodcasterAI | 11/7/2026 | 14/7/2026 | The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.51% | — | Freshsales Contact Form 7 IntegrationAI | 6/6/2026 | 23/7/2026 | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.4) | 0.47% | — | Ucdok TomatoAIFreshtomatoAI | 30/5/2026 | 22/7/2026 | A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Alta (8.7) | 0.44% | — | FreshtomatoAIUcdok TomatoAI | 29/5/2026 | 21/7/2026 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer… | |
| Aplazada | Media (6.9) | 0.28% | — | FreshtomatoAIUcdok TomatoAI | 29/5/2026 | 21/7/2026 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only… | |
| Aplazada | Alta (8.2) | 0.27% | — | FreshrssAI | 9/3/2026 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently being called with a constructed string (SHA-256 nonce + part of a bcrypt hash) instead of the raw user password. Due to bcrypt’s 72-byte input truncation,… | |
| Analizada | Alta (7.5) | 0.39% | — | Freshrss | 9/3/2026 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed… | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Aplazada | Alta (7.5) | 0.43% | — | Pavothemes FreshioAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio allows PHP Local File Inclusion.This issue affects Freshio: from n/a through <= 2.4.2. | |
| Analizada | Baja (2.9) | 0.55% | — | Freshrss | 27/12/2025 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, leading to account… | |
| Analizada | Alta (7.5) | 0.46% | — | Freshrss | 27/12/2025 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in version 1.28.0. | |
| Analizada | Media (6.5) | 0.45% | — | Freshrss | 18/12/2025 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Freshdesk Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Media (4.3) | 0.13% | — | FreshchatAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in freshchat Freshchat freshchat allows Cross Site Request Forgery.This issue affects Freshchat: from n/a through <= 2.3.4. | |
| Analizada | Alta (7.4) | 0.70% | — | Freshrss | 16/12/2025 | 17/6/2026 | FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various administrative actions as an unprivileged user. These actions include logging in as the admin, creating a… | |
| Aplazada | Media (4.7) | 0.20% | — | Crmperks WP Gravity Forms FreshdeskAI | 9/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Phishing.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Media (6.5) | 0.30% | — | Freshface Custom CSSAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom CSS: from n/a through <= 1.4.0. | |
| Analizada | Media (6.9) | 0.46% | — | Freshrss | 30/9/2025 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by setting path in theme field, allowing attackers to gain additional information about the server by checking if certain directories exist. This issue is fixed in version 1.27.0. | |
| Analizada | Media (5.4) | 0.28% | — | Freshrss | 30/9/2025 | 17/6/2026 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking protection (confirmation dialog), it is possible to trick the admin into clicking the Promote button in another user's management page after the admin double clicks on a button inside an… |