Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6559 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Media (6.5) | 0.55% | — | Redhat Build OF Keycloak | 5/8/2026 | 31/8/2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a… | |
| Modificada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 5/8/2026 | 31/8/2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Analizada | Crítica (9.1) | 0.26% | — | Redhat Build OF Keycloak | 5/8/2026 | 10/8/2026 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for… | |
| Aplazada | Alta (7.8) | 0.17% | — | Tinyobjloader-cAI | 5/8/2026 | 26/8/2026 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same file. | |
| Aplazada | Alta (7.2) | 0.50% | — | Wpdownloadmanager WP DownloadmanagerAI | 5/8/2026 | 26/8/2026 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no… | |
| Aplazada | Alta (7.3) | 0.41% | — | Material DashboardAI | 5/8/2026 | 12/8/2026 | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI | 5/8/2026 | 12/8/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Connekthq Ajax Load MoreAI | 5/8/2026 | 26/8/2026 | The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database. | |
| Aplazada | Media (6.1) | 0.26% | — | Zoneland O2oaAI | 4/8/2026 | 9/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL. | |
| Analizada | Baja (3.7) | 0.25% | — | Redhat Build OF Keycloak | 4/8/2026 | 10/8/2026 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this… | |
| Analizada | Media (5.1) | 0.37% | — | LUD Oaskit | 3/8/2026 | 17/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render… | |
| Aplazada | Media (6.1) | 0.27% | — | Meril Blog Floating ButtonAI | 3/8/2026 | 26/8/2026 | The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that… | |
| Modificada | Media (6.5) | 0.48% | — | Redhat Build OF Keycloak | 2/8/2026 | 16/9/2026 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client… | |
| Modificada | Media (6.5) | 0.39% | — | Redhat Build OF Keycloak | 2/8/2026 | 16/9/2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time.… | |
| Modificada | Alta (7.2) | 0.55% | — | Redhat Build OF Keycloak | 2/8/2026 | 16/9/2026 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized… | |
| Modificada | Media (5.4) | 0.30% | — | Redhat Build OF Keycloak | 2/8/2026 | 16/9/2026 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed… | |
| Aplazada | Media (4.3) | 0.27% | — | FluentboardsAI | 2/8/2026 | 26/8/2026 | The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions… | |
| Aplazada | Media (5.3) | 0.26% | — | Better-auth Oauth-providerAI | 1/8/2026 | 8/9/2026 | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing… | |
| Aplazada | Media (6.4) | 0.42% | — | Download ManagerAI | 1/8/2026 | 12/8/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (5.4) | 0.27% | — | Download ManagerAI | 1/8/2026 | 26/8/2026 | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 31/8/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 1/10/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id. | |
| Modificada | Media (5.4) | 0.29% | — | Redhat Build OF Keycloak | 31/7/2026 | 16/9/2026 | A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation… |