Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.39% | — | SearchplusAI | 24/6/2026 | 25/6/2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both… | |
| Aplazada | Ninguna (0) | 0.39% | — | Userlog-details.phpAI | 23/6/2026 | 25/6/2026 | Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload… | |
| Modificada | Media (5.8) | 0.21% | — | Guzzlephp Guzzle | 23/6/2026 | 5/8/2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a… | |
| Analizada | Media (4.8) | 0.23% | — | Guzzlephp Psr-7 | 23/6/2026 | 30/6/2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those… | |
| Analizada | Media (5.9) | 0.15% | — | Guzzlephp Guzzle | 23/6/2026 | 26/6/2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without… | |
| Aplazada | Alta (7.6) | 0.28% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an attacker could plant… | |
| Aplazada | Alta (7.4) | 0.30% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA.… | |
| Aplazada | Media (6.5) | 0.34% | 💥 PoC | LaravelAIFilamentphp FilamentAILaravel LivewireAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as… | |
| Aplazada | Media (6.4) | 0.25% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plant malicious HTML or… | |
| Aplazada | Media (5.3) | 0.34% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an account exists for… | |
| Analizada | Media (5.8) | 0.21% | — | Phpseclib | 22/6/2026 | 26/6/2026 | phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who… | |
| Aplazada | Crítica (9.2) | 0.46% | 💥 PoC | Phpoffice PhpspreadsheetAI | 22/6/2026 | 23/6/2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://,… | |
| Aplazada | Alta (8.7) | 0.44% | — | PhpmyfaqAI | 21/6/2026 | 23/6/2026 | phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access. | |
| Aplazada | Media (6.5) | 0.42% | — | Pontedilana Php-weasyprintAI | 19/6/2026 | 23/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the content of option values server-side via `file_get_contents()` when the value looks like a URL, without restricting the URL scheme. The `attachment` option of `Pdf` is the… | |
| Aplazada | Alta (8.1) | 0.95% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar://`, etc. bypass the… | |
| Aplazada | Alta (8.2) | 0.22% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAISymfony ProcessAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX… | |
| Analizada | Alta (8.8) | 0.48% | — | Soft-php Jcart FOR Opencart | 19/6/2026 | 19/8/2026 | Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and… | |
| Aplazada | Baja (3) | 0.15% | — | PhpweasyprintAI | 19/6/2026 | 23/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that… | |
| Aplazada | Media (6.5) | 0.39% | — | PhpmyfaqAI | 18/6/2026 | 23/6/2026 | phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpoints in the public API.… | |
| Aplazada | Media (6.3) | 0.37% | — | CakephpAI | 17/6/2026 | 23/6/2026 | CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | PHP Standard LibraryAI | 17/6/2026 | 23/6/2026 | PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, allowing… | |
| Analizada | Alta (8.8) | 2.5% | ⚠ Explotación activa | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 16/6/2026 | 22/9/2026 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | HP ONE AgentAI | 15/6/2026 | 18/6/2026 | Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities. | |
| Aplazada | Crítica (9.8) | 0.56% | — | PHPAIGvectors WpforoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Geodir Events CalendarAIPHPAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. |