Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

9646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)——LiquidjsAI6/10/20266/10/2026
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, enabling ownPropertyOnly does not consistently restrict inherited array indices because negative indexing, .first, .last, the first filter, the last filter, join, reverse, slice, compact, and for-loop iteration can…
Pendiente de análisisCrítica (10)——Payloadcms Plugin Form BuilderAI6/10/20266/10/2026
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Pendiente de análisisCrítica (9.1)——Microsoft MsquicAI6/10/20266/10/2026
MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can…
Pendiente de análisisAlta (8.2)0.36%—The-guild Graphql-toolsAI5/10/20266/10/2026
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude __proto__, constructor, or prototype keys. An unauthenticated GraphQL…
Pendiente de análisisMedia (6.9)0.15%—Moby BuildkitAI5/10/20266/10/2026
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Pendiente de análisisMedia (6.9)0.29%—Docker BuildxAI5/10/20266/10/2026
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation…
AplazadaMedia (5.3)0.19%—Villatheme BuildkitAI5/10/20266/10/2026
Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
Pendiente de análisisMedia (6.8)0.11%—Moby BuildkitAI5/10/20266/10/2026
The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds…
Pendiente de análisisMedia (6.9)0.13%—Moby BuildkitAI5/10/20266/10/2026
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Pendiente de análisisMedia (6)0.11%—Moby BuildkitAI5/10/20266/10/2026
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Pendiente de análisisMedia (5.7)0.09%—Moby BuildkitAI5/10/20266/10/2026
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Pendiente de análisisAlta (7.5)0.17%—Moby BuildkitAI5/10/20266/10/2026
A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent…
Pendiente de análisisAlta (7.1)0.24%—Moby BuildkitAI5/10/20266/10/2026
If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
Pendiente de análisisMedia (5.3)0.29%—Joomshaper SP Page Builder PROAI5/10/20266/10/2026
Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed…
AplazadaAlta (7.5)0.24%—Stylemixthemes Cost Calculator BuilderAI4/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
AplazadaCrítica (9.1)0.53%—Fastlinemedia Beaver BuilderAI3/10/20266/10/2026
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…
AplazadaAlta (8.8)0.28%—Kubio AI Page BuilderAI3/10/20266/10/2026
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before…
AplazadaMedia (6.8)0.24%—Kubio AI Page BuilderAI3/10/20266/10/2026
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator…
AplazadaMedia (6.1)0.31%—Wpclever WPC Smart Quick ViewAI3/10/20266/10/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.5)0.27%—Fastlinemedia Beaver BuilderAI3/10/20266/10/2026
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (7.2)0.24%—Crocoblock JetformbuilderAI2/10/20263/10/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (7.2)0.31%—Kubio AI Page BuilderAI2/10/20263/10/2026
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (4.3)0.18%—Inspireui Mstore APIAI2/10/20262/10/2026
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.
AplazadaMedia (6.2)0.21%—Mobyproject BuildkitAI2/10/20262/10/2026
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated…
AplazadaAlta (8.3)0.31%—Eclipse Basyx AAS WEB UIAI1/10/20261/10/2026
In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted…