Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.39% | — | Cubewp FrameworkAI | 9/8/2026 | 26/8/2026 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks. | |
| Aplazada | Alta (7.5) | 0.94% | — | Cubewp FrameworkAI | 2/8/2026 | 12/8/2026 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Aplazada | Media (6.5) | 0.47% | — | Cubewp FrameworkAI | 1/8/2026 | 12/8/2026 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a… | |
| Analizada | Crítica (10) | 0.31% | — | Roundcube Webmail | 14/7/2026 | 17/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click). | |
| Pendiente de análisis | Media (4.7) | 0.21% | — | Roundcube WebmailAI | 14/7/2026 | 15/7/2026 | Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. | |
| Analizada | Crítica (9.8) | 0.50% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover. | |
| Analizada | Crítica (10) | 0.25% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and… | |
| Analizada | Media (6.5) | 0.52% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment. | |
| Analizada | Media (6.5) | 0.47% | — | Roundcube Webmail | 14/7/2026 | 20/7/2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. | |
| Pendiente de análisis | Baja (3.3) | 0.16% | — | Cubespace Cw0057 Reaction WheelAI | 2/7/2026 | 6/7/2026 | CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. This could allow an attacker with physical access to the product to upload arbitrary malicious firmware to the device without authentication. | |
| Pendiente de análisis | Crítica (9.3) | 0.96% | — | Control WEB PanelAIRoundcubeAI | 1/7/2026 | 2/7/2026 | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection… | |
| Aplazada | Media (4.4) | 0.26% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | |
| Aplazada | Alta (7.2) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute. | |
| Aplazada | Baja (3.7) | 0.54% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | |
| Aplazada | Media (6.5) | 0.48% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | |
| Aplazada | Media (6.5) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message. | |
| Aplazada | Alta (7.5) | 0.51% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.) | |
| Aplazada | Alta (7.2) | 0.27% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540. | |
| Aplazada | Alta (8.1) | 0.89% | — | Roundcube WebmailAI | 25/5/2026 | 25/9/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. | |
| Aplazada | Crítica (9.1) | 0.54% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template… | |
| Aplazada | Alta (7.2) | 0.54% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an explicit <Files print.*.php> allow… | |
| Aplazada | Alta (8.1) | 0.20% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the… | |
| Aplazada | Media (4.9) | 0.40% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled $_GET['sort'] array without column or direction validation. Both the column key and the direction value flow… | |
| Aplazada | Crítica (9.1) | 0.76% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the web-accessible… | |
| Aplazada | Crítica (9.1) | 0.96% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By… |