Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.50% | — | Super-forms Super FormsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | |
| Aplazada | Media (6.2) | 0.44% | — | Hepta Platforms INC HeptabaseAI | 24/8/2026 | 26/8/2026 | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content. | |
| Aplazada | Crítica (9.8) | 0.90% | — | WS Form LiteAI | 22/8/2026 | 24/8/2026 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (6.6) | 0.36% | — | Wpmudev Forminator FormsAI | 22/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it. | |
| Aplazada | Alta (7.2) | 0.66% | — | Incsub ForminatorAI | 22/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |
| Pendiente de análisis | Media (6.9) | 0.54% | — | TerragruntAIOpentofuAIHashicorp TerraformAI | 21/8/2026 | 25/9/2026 | Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external… | |
| Aplazada | Media (5.9) | 0.50% | — | InfracostAIHashicorp TerraformAIHashicorp Terraform CloudAI | 21/8/2026 | 18/9/2026 | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a configured Terraform Cloud or registry token to a destination hostname derived… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Automation WEB Platform Notifications AND OTP FOR WoocommerceAI | 21/8/2026 | 24/8/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly… | |
| Aplazada | Alta (7.5) | 0.63% | — | Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI | 21/8/2026 | 26/8/2026 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026. | |
| Aplazada | Alta (8.1) | 0.54% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. | |
| Aplazada | Baja (3.5) | 0.24% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Aplazada | Alta (7.2) | 0.34% | — | Wpforms PROAI | 21/8/2026 | 24/8/2026 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.4) | 0.19% | — | Estonian Information System Authority Digidoc4AI | 20/8/2026 | 1/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Incsub ForminatorAI | 20/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | |
| Aplazada | Media (6.9) | 0.45% | — | Tassos Convert FormsAIJoomlaAI | 20/8/2026 | 26/8/2026 | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |
| Aplazada | Alta (7.1) | 0.25% | — | 10web Form MakerAI | 20/8/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 19/8/2026 | 25/8/2026 | A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Verbb FormieAICraftcms Craft CMSAI | 19/8/2026 | 10/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An… | |
| Aplazada | Alta (7.5) | 0.60% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Crítica (9.9) | 0.78% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Alta (7.5) | 0.42% | — | Contact Form 7AI | 19/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | PAY With Contact Form 7AI | 19/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | |
| Aplazada | Alta (7.7) | 0.56% | 💥 PoC | Balbooa FormsAI | 19/8/2026 | 26/8/2026 | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither… | |
| Aplazada | Crítica (10) | 0.50% | — | Balbooa FormsAI | 19/8/2026 | 29/9/2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Commerce Platform | 18/8/2026 | 1/9/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… |