Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
8597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Information System Society Membership SystemAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Media (4.8) | 0.24% | — | Redirection FOR Contact Form 7AI | 6/9/2026 | 8/9/2026 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode… | |
| Aplazada | Media (4.8) | 0.24% | — | Ninjaforms Ninja FormsAI | 6/9/2026 | 8/9/2026 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. | |
| Aplazada | Media (4.8) | 0.15% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.… | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion… | |
| Aplazada | Media (4.3) | 0.16% | — | Ninja Forms Save ProgressAI | 5/9/2026 | 8/9/2026 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Media (6.9) | 0.56% | — | Getgrav Grav Form PluginAI | 5/9/2026 | 18/9/2026 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call… | |
| Aplazada | Alta (8.7) | 0.94% | — | AxolotlAIHuggingface TransformersAI | 5/9/2026 | 23/9/2026 | Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as… | |
| Aplazada | Alta (7.2) | 0.58% | — | Contact Form BY SupsysticAI | 5/9/2026 | 8/9/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.49% | — | Custom Contact FormsAI | 5/9/2026 | 8/9/2026 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Media (4.7) | 0.17% | — | Crocoblock JetformbuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other… | |
| Aplazada | Alta (7.5) | 0.32% | — | Jetformbuilder Dynamic Blocks Form BuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft… | |
| Aplazada | Alta (7.2) | 0.25% | — | Ninjaforms Ninja FormsAI | 5/9/2026 | 8/9/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.29% | — | Brainstormforce SureformsAI | 5/9/2026 | 8/9/2026 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.19% | — | Gravityforms Gravity FormsAI | 5/9/2026 | 8/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path… | |
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,… | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 14/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the… | |
| Aplazada | Alta (8.1) | 0.55% | 💥 PoC | MachformAI | 4/9/2026 | 9/9/2026 | An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… |