Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

14.243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.29%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…
Pendiente de análisisAlta (8.7)0.27%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security…
Pendiente de análisisAlta (8.4)0.24%—Servicenow AI PlatformAI24/9/202625/9/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…
Pendiente de análisisCrítica (9.3)0.27%—Servicenow AI PlatformAI24/9/202624/9/2026
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data…
AplazadaMedia (6.1)0.22%—MailspringAI24/9/202630/9/2026
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a…
AplazadaAlta (7.5)0.39%—Zbateson Mail Mime ParserAI24/9/202630/9/2026
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects…
AplazadaAlta (7.2)0.18%—Zbateson Mail Mime ParserAI24/9/20265/10/2026
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or…
AplazadaCrítica (9.3)0.27%—IXO BlockchainAI24/9/202630/9/2026
The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included…
AplazadaMedia (4.2)0.24%—Discourse AIAI24/9/202624/9/2026
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict…
AplazadaMedia (4.3)0.16%—MailerliteAI24/9/202624/9/2026
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaMedia (5.5)0.42%—ShopxoAIBaidu UeditorAI24/9/202624/9/2026
A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The…
AplazadaBaja (2.1)0.27%—Kvcache-ai MooncakeAI23/9/202624/9/2026
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made…
AplazadaBaja (2.1)0.25%—Kvcache-ai MooncakeAI23/9/202629/9/2026
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is…
AplazadaMedia (5.5)0.29%—Kvcache-ai MooncakeAI23/9/202624/9/2026
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly…
AplazadaAlta (7.6)0.23%—Shazzad Hossain Khan W4 Post ListAI23/9/202624/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: from n/a through 3.0.6.
AplazadaAlta (7.1)0.29%—TainacanAI23/9/202623/9/2026
Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
AplazadaAlta (7.6)0.29%—Email LOGAI23/9/202623/9/2026
Administrator SQL Injection in Email Log <= 2.63 versions.
AplazadaMedia (5.3)0.23%—AI EngineAI23/9/202623/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
AplazadaMedia (6.5)0.21%—WSP MCP AI Agents ConnectorAI23/9/202623/9/2026
Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
AplazadaMedia (5.3)0.21%—Cozmoslabs Paid Membership SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.
AplazadaBaja (3.7)0.15%—Paidmembershipssubscriptions Paid Memberships SubscriptionsAI23/9/202623/9/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
AplazadaMedia (5.3)0.22%—Email SubscribersAI23/9/202623/9/2026
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
AplazadaBaja (2.1)0.20%—Therealsain PixtreamAI22/9/202623/9/2026
A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the file /post_upload.php. The manipulation of the argument media results in unrestricted upload. The attack can be launched remotely. The exploit has been released…
Pendiente de análisisMedia (4.3)1.0%—CAI Content CredentialsAI22/9/202622/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim…
En análisisMedia (6.5)1.3%—CAI Content CredentialsAI22/9/202625/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must…