Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.34% | — | FormlayerAI | 2/9/2026 | 3/9/2026 | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings,… | |
| Pendiente de análisis | Media (6.4) | 0.30% | — | Redhat Ansible Automation PlatformAIAnsible AWXAI | 1/9/2026 | 24/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A… | |
| Aplazada | Baja (3.5) | 0.27% | — | Runzero PlatformAI | 1/9/2026 | 9/9/2026 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low). | |
| Aplazada | Media (5.5) | 0.49% | — | Releasit COD Form & UpsellsAI | 1/9/2026 | 4/9/2026 | A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to… | |
| Aplazada | Alta (8.1) | 0.50% | — | Gravityforms Gravity FormsAI | 1/9/2026 | 1/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and… | |
| Pendiente de análisis | Alta (7.8) | 0.10% | — | Huggingface TransformersAI | 1/9/2026 | 23/9/2026 | A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent… | |
| Aplazada | Media (4.8) | 0.24% | — | MW WP FormAI | 1/9/2026 | 1/9/2026 | The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have… | |
| Aplazada | Crítica (10) | 0.52% | 💥 PoC | Hashthemes Hash FormAI | 31/8/2026 | 1/9/2026 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smart Marketing SMS AND Newsletters FormsAI | 31/8/2026 | 2/9/2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Fluentforms Fluent Forms PROAI | 31/8/2026 | 1/9/2026 | Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fluentforms Fluent Forms PRO ADD ON PackAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Digitalni A Informacni Agentura Eobcanka IdentifikaceAI | 31/8/2026 | 1/9/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming… | |
| Aplazada | Alta (7.5) | 0.52% | — | Html FormfuAI | 31/8/2026 | 3/9/2026 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer,… | |
| Aplazada | Baja (3.5) | 0.24% | — | MW WP FormAI | 30/8/2026 | 31/8/2026 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | |
| Aplazada | Baja (2.1) | 0.34% | — | Phpgurukul Student Information SystemAI | 29/8/2026 | 31/8/2026 | A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Sigma Forms PROAI | 29/8/2026 | 31/8/2026 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation… | |
| Aplazada | Alta (8.7) | 0.47% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without… | |
| Aplazada | Media (5.3) | 0.36% | — | FormworkAI | 29/8/2026 | 23/9/2026 | Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel. | |
| Aplazada | Media (4.3) | 0.25% | — | WP Full PAY Stripe Payment FormsAI | 29/8/2026 | 31/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation… | |
| Aplazada | Alta (8.1) | 0.55% | — | HeyformAI | 28/8/2026 | 16/9/2026 | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and… | |
| Aplazada | Media (5.3) | 0.29% | — | Incsub ForminatorAI | 28/8/2026 | 28/8/2026 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Ceviz Informatics INC WEB DesignAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026. | |
| Aplazada | Media (6.1) | 0.25% | — | Dayneks Software Industry AND Trade INC E-commerce PlatformAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (5.3) | 0.41% | — | Wpeverest Everest FormsAI | 28/8/2026 | 28/8/2026 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are… |