Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
9650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.34% | — | Dell Wyse Management Suite | 15/9/2026 | 21/9/2026 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Crítica (9.8) | 0.41% | — | Dell Wyse Management Suite | 15/9/2026 | 21/9/2026 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (4.9) | 0.24% | — | Dell Wyse Management Suite | 15/9/2026 | 21/9/2026 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. | |
| Aplazada | Media (5.4) | 0.24% | — | BharatmlstackAITrufflebox-uiAI | 15/9/2026 | 22/9/2026 | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx. | |
| Aplazada | Media (5.3) | 0.37% | — | BharatmlstackAITrufflebox UIAI | 15/9/2026 | 22/9/2026 | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page. | |
| Aplazada | Media (6.1) | 0.25% | — | BharatmlstackAIBharatmlstack Trufflebox-uiAI | 15/9/2026 | 22/9/2026 | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx. | |
| Aplazada | Alta (8.8) | 0.49% | — | Yeger Turbo-graphAIYeger Turbo-graph-uiAI | 15/9/2026 | 30/9/2026 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in… | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | Semaphore UIAI | 15/9/2026 | 24/9/2026 | Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint. | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | Esphome Device BuilderAIEsphomeAI | 14/9/2026 | 30/9/2026 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD`… | |
| Aplazada | Media (5.3) | 0.52% | — | Quic-go Webtransport-goAI | 14/9/2026 | 30/9/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus… | |
| Aplazada | Media (6.9) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and File::upload() without either of the… | |
| Aplazada | Alta (7) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification… | |
| Aplazada | Alta (8.6) | 0.37% | — | Joomla SP Page BuilderAIJoomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ...… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAIJoomlaAI | 14/9/2026 | 5/10/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 5.6.1p2 and 6.0.0 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Quick IndexAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute.… | |
| Aplazada | Media (6.6) | 0.23% | — | Digitaldruid HoteldruidAI | 14/9/2026 | 22/9/2026 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | |
| Aplazada | Baja (2.1) | 0.41% | — | Cym1102 NginxwebuiAI | 13/9/2026 | 14/9/2026 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may… | |
| Aplazada | Alta (8.1) | 0.45% | — | Jquindlen WpstorecartAI | 12/9/2026 | 14/9/2026 | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget… | |
| Aplazada | Alta (7.1) | 0.13% | — | Export Import Wpbakery Page BuilderAI | 12/9/2026 | 14/9/2026 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that… | |
| Aplazada | Media (5.3) | 0.31% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Visualcomposer Website BuilderAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Bold Page BuilderAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | |
| Aplazada | Media (6.9) | 0.67% | — | Arduinocore-avrAI | 11/9/2026 | 30/9/2026 | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing… |