Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

8598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.50%—Super-forms Super FormsAI24/8/202624/8/2026
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
AplazadaMedia (6.2)0.44%—Hepta Platforms INC HeptabaseAI24/8/202626/8/2026
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
AplazadaCrítica (9.8)0.90%—WS Form LiteAI22/8/202624/8/2026
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
AplazadaMedia (6.6)0.36%—Wpmudev Forminator FormsAI22/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
AplazadaAlta (7.2)0.66%—Incsub ForminatorAI22/8/202626/8/2026
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Pendiente de análisisMedia (6.9)0.54%—TerragruntAIOpentofuAIHashicorp TerraformAI21/8/202625/9/2026
Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external…
AplazadaMedia (5.9)0.50%—InfracostAIHashicorp TerraformAIHashicorp Terraform CloudAI21/8/202618/9/2026
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a configured Terraform Cloud or registry token to a destination hostname derived…
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AplazadaAlta (7.5)0.63%—Fuyaweb Internet AND Informatics Services Architectpanel WEB Admin PanelAI21/8/202626/8/2026
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
AplazadaAlta (8.1)0.54%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
AplazadaBaja (3.5)0.24%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
AplazadaAlta (7.2)0.34%—Wpforms PROAI21/8/202624/8/2026
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (8.4)0.19%—Estonian Information System Authority Digidoc4AI20/8/20261/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0.
AplazadaCrítica (9.8)0.56%—Incsub ForminatorAI20/8/202620/8/2026
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
AplazadaMedia (6.9)0.45%—Tassos Convert FormsAIJoomlaAI20/8/202626/8/2026
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
AplazadaAlta (7.1)0.25%—10web Form MakerAI20/8/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49.
AplazadaMedia (5.5)0.43%—Code-projects Hospital Information SystemAI19/8/202625/8/2026
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely.…
AplazadaCrítica (9.8)1.3%—Verbb FormieAICraftcms Craft CMSAI19/8/202610/9/2026
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An…
AplazadaAlta (7.5)0.60%—Bottinelli Informatica Vedo SuiteAI19/8/20269/9/2026
An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter
AplazadaCrítica (9.9)0.78%—Bottinelli Informatica Vedo SuiteAI19/8/20269/9/2026
SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter
AplazadaAlta (7.5)0.42%—Contact Form 7AI19/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
AplazadaAlta (7.5)0.42%—PAY With Contact Form 7AI19/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
AplazadaAlta (7.7)0.56%💥 PoCBalbooa FormsAI19/8/202626/8/2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither…
AplazadaCrítica (10)0.50%—Balbooa FormsAI19/8/202629/9/2026
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject…
AnalizadaAlta (7.5)0.33%—Oracle Commerce Platform18/8/20261/9/2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…