Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

8598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Mailchimp Subscribe FormsAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
AplazadaAlta (7.2)0.49%—Fluentform Fluent FormsAI13/8/202614/8/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (5.1)0.31%—National Institute OF Information AND Communications Technology VoicetraAI13/8/202628/8/2026
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display…
AnalizadaAlta (7.3)0.43%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (7.8)0.14%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
AplazadaCrítica (9.2)0.42%—Camaleon CMS Cama Contact FormAITuzitio Camaleon CMSAI12/8/202626/8/2026
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls.…
AplazadaAlta (7.2)0.38%—Camaleon AttackAICamaleon Front CacheAICamaleon Cama Meta TAGAICamaleon Cama Contact FormAI+112/8/202626/8/2026
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime…
AnalizadaAlta (8.8)0.49%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
AnalizadaMedia (5.5)0.15%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux12/8/20261/9/2026
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the…
Pendiente de análisisCrítica (9.9)0.65%—Google Cloud Platform GCPAIProwlerAI12/8/20269/9/2026
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec blocks, and POST…
AplazadaAlta (8.1)0.39%—10web Form MakerAI12/8/202626/8/2026
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
AplazadaCrítica (9.8)0.67%—Formidable Digital SignaturesAI11/8/202612/8/2026
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled…
AnalizadaMedia (5.4)0.12%—Intel Performance Counter Monitor11/8/20262/10/2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This…
Pendiente de análisisMedia (4.3)0.30%—SAP Businessobjects Business Intelligence PlatformAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low…
Pendiente de análisisAlta (7.9)0.20%—SAP Businessobjects Business Intelligence PlatformAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow…
Pendiente de análisisMedia (6.5)0.39%—SAP Businessobjects Business Intelligence PlatformAISAP WEB IntelligenceAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of…
Pendiente de análisisMedia (5.3)0.36%—SAP Abap PlatformAI11/8/202626/8/2026
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisMedia (4.2)0.25%—SAP NetweaverAISAP Abap PlatformAI11/8/202626/8/2026
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational…
Pendiente de análisisMedia (5.5)0.69%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI11/8/202626/8/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or…
Pendiente de análisisAlta (8.6)0.78%—Pega PlatformAI10/8/20268/9/2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.
AplazadaAlta (7.5)0.65%—Xwiki PlatformAI10/8/202618/9/2026
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes…
AplazadaMedia (4.4)0.12%—Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI10/8/20261/9/2026
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before…
AplazadaAlta (7.5)0.43%—Itpathsolutions Contact Form TO ANY APIAI10/8/202626/8/2026
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
AplazadaAlta (7.5)0.43%—Login AND Register FormsAI10/8/202626/8/2026
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
AplazadaAlta (8.1)0.38%—Login Register FormsAI10/8/202626/8/2026
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset the limit at will and brute-force the…