Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | 💥 PoC | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Aplazada | Alta (8.8) | 0.24% | — | TAC Information Services Internal AND External Trade INC Goldenhorn OneitAI | 4/9/2026 | 8/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. | |
| Aplazada | Crítica (9.3) | 0.36% | — | Getgrav Grav-plugin-formAI | 4/9/2026 | 8/9/2026 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name… | |
| Aplazada | Media (5.9) | 0.23% | — | Thedotstore Ninja FormsAI | 4/9/2026 | 8/9/2026 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Crítica (9.9) | 0.63% | — | Microsoft Power Platform | 3/9/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.32% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket… | |
| Analizada | Media (5.9) | 0.18% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.29% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.39% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and… | |
| Aplazada | Media (5.3) | 0.34% | — | Brainstormforce SureformsAI | 3/9/2026 | 7/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms File Uploads ExtensionAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Calculation FOR Contact Form 7AI | 3/9/2026 | 3/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | |
| Aplazada | Media (6.8) | 0.46% | — | Openedx Open EDX PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". The fetched bytes are then returned inside a ZIP response. This enables SSRF with… | |
| Aplazada | Media (4.7) | 0.28% | — | Openedx PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The validate_timestamp_and_nonce function in… | |
| Aplazada | Alta (7.6) | 0.40% | — | Openedx Open EDX PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated… | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins PerformanceAI | 2/9/2026 | 3/9/2026 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |
| Aplazada | Media (6.5) | 0.36% | — | Hipaa FormsAI | 2/9/2026 | 3/9/2026 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints. | |
| Aplazada | Alta (8.8) | 0.46% | — | Ninjaforms Ninja Forms - Layout & StylesAI | 2/9/2026 | 3/9/2026 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | Easy Waveform PlayerAI | 2/9/2026 | 3/9/2026 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Sigmaforms PROAI | 2/9/2026 | 2/9/2026 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the… |