Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Netiket Information Technologies EdowebAI | 18/8/2026 | 26/8/2026 | Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav Form PluginAI | 18/8/2026 | 8/9/2026 | Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw… | |
| Aplazada | Media (5.7) | 0.17% | — | Kriptok Crypto AND Information Technologies Industry Trade INC CryptosimAI | 18/8/2026 | 26/8/2026 | Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229. | |
| Aplazada | Alta (7.2) | 0.32% | — | Mdmag Quill FormsAI | 18/8/2026 | 20/8/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Crítica (9.8) | 6.1% | 💥 PoC | Incsub ForminatorAI | 18/8/2026 | 20/8/2026 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Jhumanj OpnformAI | 17/8/2026 | 1/10/2026 | OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by… | |
| Pendiente de análisis | Media (6.8) | 0.29% | — | Huggingface TransformersAI | 17/8/2026 | 24/9/2026 | Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Brainformatik Crm+AI | 17/8/2026 | 9/9/2026 | The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL… | |
| Aplazada | Media (5.3) | 0.52% | — | Wpmudev ForminatorAI | 16/8/2026 | 20/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.76% | — | Reputeinfosystems ArformsAI | 16/8/2026 | 1/10/2026 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (4.9) | 0.44% | — | NexformsAI | 16/8/2026 | 20/8/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (4.3) | 0.47% | — | Wpeverest Everest FormsAI | 16/8/2026 | 20/8/2026 | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.49% | — | 10web Form MakerAI | 15/8/2026 | 20/8/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (10) | 1.6% | 💥 PoC | Mindsdb Minds PlatformAI | 14/8/2026 | 24/9/2026 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool… | |
| Analizada | Media (4.4) | 0.15% | — | Redhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 31/8/2026 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav FormAI | 14/8/2026 | 31/8/2026 | Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and… | |
| Aplazada | Media (6.5) | 0.45% | — | Bitapps BIT FormAI | 14/8/2026 | 17/8/2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Modificada | Media (5.5) | 0.16% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 2/10/2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This… | |
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Aplazada | Alta (8.2) | 0.56% | — | Data Mufform LocalizerAI | 13/8/2026 | 26/8/2026 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Html FormhandlerAIPerlAILocale MaketextAI | 13/8/2026 | 8/9/2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the… | |
| Aplazada | Crítica (9.3) | 0.67% | — | Fluent Forms PROAI | 13/8/2026 | 9/9/2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple Student Information SystemAI | 13/8/2026 | 14/8/2026 | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (6.5) | 0.33% | — | Contact Form 7 Paypal AND Stripe Add-onAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. |