Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
2440 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.39% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 21/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, so a key created with limited scopes… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 17/7/2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 16/7/2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.19% | — | Pluginops Landing Page BuilderAI | 16/7/2026 | 17/7/2026 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible… | |
| Aplazada | Media (6.7) | 0.72% | — | Nocobase Plugin BackupsAI | 15/7/2026 | 18/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js… | |
| Aplazada | Media (6.8) | 0.47% | — | NocobaseAINocobase Plugin Collection SQLAI | 15/7/2026 | 16/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that… | |
| Aplazada | Crítica (10) | 0.89% | 💥 PoC | Nocobase Plugin Notification IN APP MessageAI | 15/7/2026 | 20/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal()… | |
| Aplazada | Media (5.3) | 0.83% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with api.media.write permission can upload a file… | |
| Aplazada | Media (6.9) | 0.33% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour)… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an… | |
| Aplazada | Alta (8.7) | 1.1% | — | Getgrav Grav-plugin-flex-objectsAIGetgrav GravAI | 15/7/2026 | 15/7/2026 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or… | |
| Aplazada | Alta (8.1) | 0.38% | — | Shibboleth Wordpress PluginAI | 15/7/2026 | 15/7/2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an… | |
| Aplazada | Alta (7.2) | 0.54% | — | Shapedplugin Real TestimonialsAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | |
| Aplazada | Alta (7.1) | 0.25% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-admin2AIGetgrav GravAI | 11/7/2026 | 13/7/2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-adminAI | 10/7/2026 | 10/7/2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending a direct POST request to… | |
| Aplazada | Media (5.1) | 0.50% | — | Grav-plugin-databaseAI | 10/7/2026 | 13/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly concatenating user-configurable YAML values from fields such as host, dbname, charset, server, database, directory, and filename without sanitization or validation, allowing an administrator… | |
| Aplazada | Crítica (9.2) | 0.53% | — | Grav-plugin-databaseAI | 10/7/2026 | 10/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-apiAI | 10/7/2026 | 10/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Security::sanitizeSVG(), so an authenticated attacker with the… | |
| Aplazada | Baja (2.1) | 0.22% | — | Elixir-plug PlugAI | 10/7/2026 | 24/9/2026 | Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain,… | |
| Aplazada | Media (6.9) | 1.1% | — | Elixir PlugAI | 10/7/2026 | 24/9/2026 | Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. The parser charges the :length limit only for part body bytes; part… | |
| Aplazada | Media (6.4) | 0.35% | — | Affiliate-toolkit WP Affiliate Plugin With Amazon PluginAI | 10/7/2026 | 14/7/2026 | The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Alta (7.3) | 0.50% | — | Glpi TAG PluginAI | 9/7/2026 | 20/7/2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() without output escaping, resulting in stored cross-site scripting. An authenticated user with TAG MANAGEMENT create or update rights can set a tag name… |