Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

8596 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—Advanced Contact Form 7 DBAI10/9/202610/9/2026
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above,…
AplazadaMedia (6.4)0.26%—Ninja Forms Scheduled ExportsAI10/9/202611/9/2026
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)1.0%💥 PoCDrag AND Drop File Upload FOR Elementor FormsAI10/9/202610/9/2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled…
AplazadaCrítica (10)1.4%—Akana API PlatformAI9/9/20269/9/2026
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied…
AplazadaMedia (6.1)0.24%—Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI9/9/20269/9/2026
URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1…
AplazadaMedia (5.3)0.19%—Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI9/9/20269/9/2026
Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before…
AplazadaMedia (4.3)0.18%—Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI9/9/20269/9/2026
Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2.
AplazadaMedia (6.5)0.31%—Contact Form 7 CaptchaAI9/9/20269/9/2026
The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaAlta (7.2)0.51%—Repeater Fields FOR Gravity FormsAI9/9/20269/9/2026
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.6)0.66%—Ninjaforms Ninja FormsAI9/9/20269/9/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP…
AplazadaAlta (7.2)0.24%—Bestwebsoft Contact Form TO DBAI9/9/20269/9/2026
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.24%—Html FormhandlerAI8/9/202610/9/2026
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the…
AplazadaMedia (6.1)0.26%—Html Formhandler Project Html FormhandlerAI8/9/202610/9/2026
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other…
AplazadaMedia (6.1)0.33%—Html FormhandlerAI8/9/202610/9/2026
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also…
AplazadaMedia (6.1)0.26%—Html FormhandlerAI8/9/202610/9/2026
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and…
AplazadaAlta (7.5)0.43%💥 PoCMachformAI8/9/20269/9/2026
A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.
AplazadaMedia (6.5)0.39%💥 PoCMachformAI8/9/20269/9/2026
A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI8/9/20268/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
Pendiente de análisisMedia (4.3)0.28%—SAP NetweaverAISAP Abap PlatformAI8/9/20268/9/2026
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details,…
Pendiente de análisisAlta (7.7)0.43%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI8/9/20269/9/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high…
AplazadaCrítica (9.8)0.56%—Next4biz Information Technologies INC CSMAI7/9/20269/9/2026
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
AplazadaAlta (7.5)0.50%—Next4biz Information Technologies INC CSMAI7/9/20268/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.
AplazadaMedia (5.5)0.53%—Code-projects Hospital Information SystemAI7/9/20269/9/2026
A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.…
AplazadaBaja (2)0.35%—Code-projects Hospital Information SystemAI7/9/20268/9/2026
A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has…
AplazadaBaja (2.1)0.33%—Itsourcecode Information System Society Membership SystemAI7/9/202628/9/2026
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit…