Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
9650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.8) | 0.92% | 💥 PoC | AvadaAIAvada Fusion BuilderAI | 26/8/2026 | 27/8/2026 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it… | |
| Aplazada | Alta (7.5) | 0.61% | — | Libp2pAILibp2p Circuit Relay V2AI | 24/8/2026 | 9/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE… | |
| Aplazada | Alta (8.8) | 0.46% | — | Liquidlabs MagicaiAI | 24/8/2026 | 26/8/2026 | Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | |
| Aplazada | Alta (8.7) | 0.41% | — | AzuracastAILiquidsoapAI | 24/8/2026 | 24/9/2026 | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in… | |
| Pendiente de análisis | Alta (7) | 0.20% | — | RpmbuildAI | 24/8/2026 | 4/9/2026 | A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can… | |
| Aplazada | Alta (7.1) | 0.25% | — | Liquidweb WpcompleteAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | Shopbuilder PROAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model. | |
| Aplazada | Media (5.3) | 0.44% | — | Joomlack Page Builder CKAI | 24/8/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter. | |
| Aplazada | Baja (2.1) | 0.41% | — | Provectus Kafka-uiAI | 24/8/2026 | 26/8/2026 | A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the component Groovy Code Handler. The manipulation results in code injection. The… | |
| Aplazada | Media (4.3) | 0.27% | — | Brave Popup BuilderAI | 23/8/2026 | 26/8/2026 | Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL. | |
| Aplazada | Alta (7.1) | 0.25% | — | Brave Popup BuilderAI | 23/8/2026 | 26/8/2026 | Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | |
| Aplazada | Media (5.3) | 0.56% | — | Themify BuilderAI | 22/8/2026 | 24/8/2026 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling… | |
| Pendiente de análisis | Media (6.3) | 0.18% | — | BuildahAI | 21/8/2026 | 25/9/2026 | Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and downloadToDirectory and stdinToDirectory can follow a Dockerfile symlink left by a partially… | |
| Aplazada | Alta (8.7) | 0.51% | — | Stability AI Stable Diffusion WebuiAI | 21/8/2026 | 24/9/2026 | to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside… | |
| Aplazada | Alta (8.7) | 0.50% | — | Stable Diffusion WebuiAI | 21/8/2026 | 24/9/2026 | is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for… | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1, XmlBuilder.element/2, XmlBuilder.element/3.… | |
| Pendiente de análisis | Baja (2.1) | 0.22% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The escape/1 clause for {:cdata, data} in… | |
| Pendiente de análisis | Baja (2.1) | 0.19% | — | Joshnuss XML BuilderAI | 21/8/2026 | 24/8/2026 | Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1,… | |
| Aplazada | Alta (7.1) | 0.50% | — | Juicedata JuicefsAI | 21/8/2026 | 24/9/2026 | The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no check that the result stayed beneath the root. Put, Get, Head, Delete,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Squirrly SEOAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | LiquidjsAI | 19/8/2026 | 9/9/2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length and separator length instead of the total string length produced by array.join(sep). The concat filter can cheaply double arrays of… | |
| Pendiente de análisis | Alta (8.7) | 0.52% | — | LiquidjsAI | 19/8/2026 | 9/9/2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string contains <, includes at least one preceding character, and has no later >. In strip_html, the search for the next… |