Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
14.241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Kirillbdev WC Ukraine ShippingAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2. | |
| Aplazada | Alta (7.1) | 0.22% | — | Webfulcreations RepairbuddyAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226. | |
| Aplazada | Media (6.5) | 0.17% | — | Webfulcreations RepairbuddyAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | Linuxfoundation ContainerdAI | 5/10/2026 | 6/10/2026 | An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity. | |
| Aplazada | Media (5.4) | 0.17% | — | Brainstormforce Astra SitesAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Aplazada | Media (5.3) | 0.19% | — | Wpmailster WP MailsterAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Brainstormforce Presto PlayerAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | |
| Aplazada | Media (6.5) | 0.16% | — | Brainstormforce Astra SitesAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | AidlAI | 5/10/2026 | 6/10/2026 | In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185225; Issue ID: MSV-9024. | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Android AidlAI | 5/10/2026 | 6/10/2026 | In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038. | |
| Pendiente de análisis | Media (6.7) | 0.10% | — | AidlAI | 5/10/2026 | 6/10/2026 | In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | |
| Aplazada | Media (6.9) | 0.14% | — | Invariant-systems-ai AiirAI | 4/10/2026 | 6/10/2026 | A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected… | |
| Aplazada | Media (5.5) | 0.41% | — | Rainygao DocsysAI | 4/10/2026 | 6/10/2026 | A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.45% | — | Rainygao DocsysAI | 4/10/2026 | 6/10/2026 | A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.28% | — | Sciphi-ai R2RAI | 4/10/2026 | 5/10/2026 | A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be… | |
| Aplazada | Media (5.5) | 0.28% | — | Sciphi-ai R2RAI | 4/10/2026 | 5/10/2026 | A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed… | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | Nasa-ammos Ait-coreAI | 3/10/2026 | 6/10/2026 | CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry… | |
| Aplazada | Alta (7.2) | 0.24% | — | Jamesward WP Mail CatcherAI | 3/10/2026 | 6/10/2026 | The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.22% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Aplazada | Media (4.3) | 0.21% | — | Alttext ALT Text AIAI | 3/10/2026 | 6/10/2026 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.28% | — | Kubio AI Page BuilderAI | 3/10/2026 | 6/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before… | |
| Aplazada | Media (6.8) | 0.24% | — | Kubio AI Page BuilderAI | 3/10/2026 | 6/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator… | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Langchain Langgraph SDKAI | 2/10/2026 | 6/10/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and… | |
| Aplazada | Media (6.5) | 0.18% | — | Aioseo ALL IN ONE SEOAI | 2/10/2026 | 6/10/2026 | The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the… | |
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. |