Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

8598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.25%—Pega PlatformAI28/8/20268/9/2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
AplazadaAlta (7.2)0.45%—Incsub ForminatorAI28/8/202628/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Pendiente de análisisCrítica (10)0.42%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data…
Pendiente de análisisCrítica (10)0.62%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow…
AplazadaAlta (8.8)0.73%—Silverstripe UserformsAISilverstripe CMSAI27/8/20269/9/2026
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to…
Pendiente de análisisCrítica (10)5.0%—Servicenow AI PlatformAI27/8/20263/9/2026
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a…
Pendiente de análisisCrítica (10)7.2%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.…
AplazadaMedia (6.1)0.25%—Bilpark Informatics Technologies Industry AND Trade DoxbaseAI27/8/202628/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026. NOTE: The vendor was contacted early about this disclosure but did not…
AplazadaMedia (4.3)0.28%—Softtr Informatics Technology Trading Limited E-commerce PackAI27/8/202628/8/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaMedia (5.3)0.29%—Kaliforms Kali FormsAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
AplazadaCrítica (9.8)0.56%—Hashthemes Hash FormAI27/8/202628/8/2026
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
AplazadaCrítica (9.8)0.56%—Infinitumform GEO ControllerAI27/8/202628/8/2026
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
AplazadaAlta (7.5)0.69%—Formidable ChartsAIFormidable FormsAI26/8/202627/8/2026
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful…
AplazadaAlta (7.2)0.41%—Strategy11 Formidable FormsAI26/8/202626/8/2026
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (4.3)0.25%—WP Full PAY Stripe Payment FormsAI26/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other…
AplazadaMedia (5.3)0.34%—WP Full PAY Stripe Payment FormsAI26/8/202626/8/2026
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.
AplazadaBaja (3.7)0.15%—Incsub ForminatorAI26/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
Pendiente de análisisCrítica (9.1)0.31%—Drupal Webform RestAI25/8/202628/8/2026
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
AplazadaAlta (8.7)0.43%—Airbyte PlatformAI25/8/202624/9/2026
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of…
AplazadaAlta (7.2)0.35%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.2)0.44%—Wpmudev ForminatorAI25/8/202626/8/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.29%—MetformAI25/8/202626/8/2026
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.28%—Nopaperforms Niaa-chatbotAI24/8/20269/9/2026
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
AplazadaAlta (8.4)0.38%—Informatik.hu-berlin FlairAI24/8/202624/9/2026
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker's code…
AplazadaMedia (4.3)0.14%—Hashthemes Hash FormAI24/8/202624/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.