Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

30.457 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.17%—Kentico XperienceAI2/10/20266/10/2026
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.
Pendiente de análisisCrítica (9.3)1.4%—Amazon Sagemaker DistributionAI2/10/20266/10/2026
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated…
AplazadaMedia (6.5)0.28%—Eventtickets Event Tickets AND RegistrationAI2/10/20262/10/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (5.4)0.22%—Popup Maker WPAI2/10/20262/10/2026
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables…
AplazadaMedia (5.3)0.21%—Emarketdesign Request A QuoteAI2/10/20262/10/2026
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
AplazadaMedia (4.3)0.15%—Code-atlantic Popup MakerAI2/10/20262/10/2026
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service…
AplazadaAlta (8.6)0.36%—ClipbucketAI1/10/20262/10/2026
ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user…
AplazadaAlta (8.8)0.50%—MooncakeAI1/10/20262/10/2026
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to…
AplazadaCrítica (9.3)0.64%—Mooncake Transfer EngineAI1/10/20262/10/2026
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or…
AplazadaAlta (8.7)0.37%—Mooncake Transfer EngineAI1/10/20266/10/2026
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys…
AplazadaAlta (8.2)0.40%—Mooncake Transfer EngineAI1/10/20262/10/2026
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in…
Pendiente de análisisMedia (6.5)0.21%—KeycloakAI1/10/20261/10/2026
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive…
En análisisCrítica (9.3)0.14%💥 PoCWatchguard Kernel Memory Access DriverAI1/10/20262/10/2026
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process…
AplazadaMedia (6.5)0.24%—Mage-people BUS Ticket Booking With Seat ReservationAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
AplazadaCrítica (9.9)0.27%—Boks KeytabmdAI1/10/20261/10/2026
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a…
AplazadaMedia (4.8)0.29%—Crocantickets EntradiumAI1/10/20261/10/2026
CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the…
AplazadaMedia (4.8)0.28%—Crocantickets EntradiumAI1/10/20261/10/2026
CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.
AplazadaAlta (7.2)0.30%—10web Form MakerAI1/10/20263/10/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.6)0.26%—PRO Like ButtonAI1/10/20261/10/2026
The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
AplazadaBaja (2.1)0.32%—Zongxr SupermarketAI1/10/20265/10/2026
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The…
AplazadaMedia (5.5)0.44%—Zongxr SupermarketAI1/10/20261/10/2026
A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results…
AplazadaMedia (5.5)0.40%—Zongxr SupermarketAI1/10/20261/10/2026
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing…
AplazadaAlta (8.5)0.25%—Event TicketsAI30/9/20262/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5.
AplazadaMedia (4.3)0.25%—Omnisend Newsletters Email Marketing SMS AND PopupsAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
AplazadaAlta (7.2)0.37%—Keywordrush Content EGGAI30/9/202630/9/2026
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.