Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

8598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.15%—Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI4/9/20268/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library…
AplazadaMedia (6.1)0.25%💥 PoCYordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI4/9/20268/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and…
AplazadaAlta (8.8)0.24%—TAC Information Services Internal AND External Trade INC Goldenhorn OneitAI4/9/20268/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe.
AplazadaCrítica (9.3)0.36%—Getgrav Grav-plugin-formAI4/9/20268/9/2026
The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name…
AplazadaMedia (5.9)0.23%—Thedotstore Ninja FormsAI4/9/20268/9/2026
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2…
AplazadaMedia (5.5)0.43%—Code-projects Hospital Information SystemAI4/9/20268/9/2026
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit…
AplazadaMedia (5.5)0.43%—Code-projects Hospital Information SystemAI4/9/20264/9/2026
A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AplazadaMedia (5.5)0.43%—Code-projects Hospital Information SystemAI4/9/20264/9/2026
A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaCrítica (9.9)0.63%—Microsoft Power Platform3/9/20268/9/2026
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.32%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket…
AnalizadaMedia (5.9)0.18%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalizadaMedia (4.3)0.29%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
AnalizadaMedia (5.9)0.20%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalizadaAlta (7.5)0.39%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and…
AplazadaMedia (5.3)0.34%—Brainstormforce SureformsAI3/9/20267/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.
AplazadaAlta (7.1)0.25%—Ninjaforms File Uploads ExtensionAI3/9/20265/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaAlta (7.1)0.25%—Calculation FOR Contact Form 7AI3/9/20263/9/2026
Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.
AplazadaMedia (6.8)0.46%—Openedx Open EDX PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". The fetched bytes are then returned inside a ZIP response. This enables SSRF with…
AplazadaMedia (4.7)0.28%—Openedx PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The validate_timestamp_and_nonce function in…
AplazadaAlta (7.6)0.40%—Openedx Open EDX PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated…
Pendiente de análisisAlta (8.8)0.64%—Jenkins PerformanceAI2/9/20263/9/2026
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
AplazadaMedia (6.5)0.36%—Hipaa FormsAI2/9/20263/9/2026
The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
AplazadaAlta (8.8)0.46%—Ninjaforms Ninja Forms - Layout & StylesAI2/9/20263/9/2026
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
AplazadaMedia (6.4)0.19%—Easy Waveform PlayerAI2/9/20263/9/2026
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaCrítica (9.8)1.0%—Sigmaforms PROAI2/9/20262/9/2026
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the…