Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 10/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently… | |
| Aplazada | Alta (7.5) | 0.43% | — | HT Contact FormAI | 10/8/2026 | 26/8/2026 | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts. | |
| Aplazada | Media (5.9) | 0.65% | — | Xwiki PlatformAI | 7/8/2026 | 18/9/2026 | XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on the wiki to write arbitrary files.… | |
| Aplazada | Alta (8.8) | 0.44% | — | Praisonai Platform APIAI | 7/8/2026 | 18/9/2026 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read,… | |
| Aplazada | Media (6.4) | 0.26% | — | Ultraaddons Ultra Addons FOR Contact Form 7AI | 7/8/2026 | 12/8/2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and including, 3.5.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.8) | 0.24% | — | Ninjaforms Ninja FormsAI | 6/8/2026 | 26/8/2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a… | |
| Aplazada | Media (5.9) | 0.18% | — | Strategy11 Formidable FormsAI | 6/8/2026 | 26/8/2026 | The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license delivery, and membership activation — without… | |
| Aplazada | Media (6.5) | 0.42% | — | Gutena FormsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Formidable Forms Signature Online Contract AutomationAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Incsub ForminatorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Incsub ForminatorAI | 6/8/2026 | 12/8/2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Loca Software Informatics Technology LTD CMSAI | 6/8/2026 | 26/8/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.2) | 0.32% | — | FormgentAI | 6/8/2026 | 29/9/2026 | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Aplazada | Alta (7.5) | 0.35% | — | WP Full PAY Stripe Payment FormsAI | 6/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to… | |
| Aplazada | Alta (7.2) | 0.48% | — | Wpdesk ForminatorAI | 6/8/2026 | 12/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.41% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.47% | — | Rongzhitong Visual Integrated Command AND Dispatch PlatformAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (6.3) | 0.18% | 💥 PoC | Amazon AWS Transform MCP Server | 5/8/2026 | 10/8/2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should… | |
| Analizada | Alta (8.8) | 0.49% | — | IBM Qradar Security Information AND Event Manager | 5/8/2026 | 10/8/2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Crítica (9.8) | 0.65% | — | IBM Qradar Security Information AND Event Manager | 5/8/2026 | 10/8/2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Piriform CcleanerAI | 5/8/2026 | 8/9/2026 | Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated… |