Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
30.457 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.17% | — | Kentico XperienceAI | 2/10/2026 | 6/10/2026 | Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. | |
| Pendiente de análisis | Crítica (9.3) | 1.4% | — | Amazon Sagemaker DistributionAI | 2/10/2026 | 6/10/2026 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated… | |
| Aplazada | Media (6.5) | 0.28% | — | Eventtickets Event Tickets AND RegistrationAI | 2/10/2026 | 2/10/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.22% | — | Popup Maker WPAI | 2/10/2026 | 2/10/2026 | The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables… | |
| Aplazada | Media (5.3) | 0.21% | — | Emarketdesign Request A QuoteAI | 2/10/2026 | 2/10/2026 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | |
| Aplazada | Media (4.3) | 0.15% | — | Code-atlantic Popup MakerAI | 2/10/2026 | 2/10/2026 | The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service… | |
| Aplazada | Alta (8.6) | 0.36% | — | ClipbucketAI | 1/10/2026 | 2/10/2026 | ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user… | |
| Aplazada | Alta (8.8) | 0.50% | — | MooncakeAI | 1/10/2026 | 2/10/2026 | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Mooncake Transfer EngineAI | 1/10/2026 | 2/10/2026 | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or… | |
| Aplazada | Alta (8.7) | 0.37% | — | Mooncake Transfer EngineAI | 1/10/2026 | 6/10/2026 | Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys… | |
| Aplazada | Alta (8.2) | 0.40% | — | Mooncake Transfer EngineAI | 1/10/2026 | 2/10/2026 | Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in… | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | KeycloakAI | 1/10/2026 | 1/10/2026 | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive… | |
| En análisis | Crítica (9.3) | 0.14% | 💥 PoC | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 2/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Aplazada | Crítica (9.9) | 0.27% | — | Boks KeytabmdAI | 1/10/2026 | 1/10/2026 | In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a… | |
| Aplazada | Media (4.8) | 0.29% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the… | |
| Aplazada | Media (4.8) | 0.28% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. | |
| Aplazada | Alta (7.2) | 0.30% | — | 10web Form MakerAI | 1/10/2026 | 3/10/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.26% | — | PRO Like ButtonAI | 1/10/2026 | 1/10/2026 | The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Baja (2.1) | 0.32% | — | Zongxr SupermarketAI | 1/10/2026 | 5/10/2026 | A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The… | |
| Aplazada | Media (5.5) | 0.44% | — | Zongxr SupermarketAI | 1/10/2026 | 1/10/2026 | A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results… | |
| Aplazada | Media (5.5) | 0.40% | — | Zongxr SupermarketAI | 1/10/2026 | 1/10/2026 | A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing… | |
| Aplazada | Alta (8.5) | 0.25% | — | Event TicketsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. | |
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. |