Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.34% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 6/6/2026 | 23/7/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versions up to, and including, 1.3.9.7 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.52% | — | WosdevicedropsAI | 27/5/2026 | 17/6/2026 | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources: | |
| Aplazada | Baja (1.8) | 0.26% | — | Backdrop Gdpr CookiesAI | 26/5/2026 | 24/7/2026 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission… | |
| Aplazada | Media (5) | 0.25% | — | Add-ons.org PDF FOR Elementor Forms AND Drag AND Drop Template BuilderAI | 20/5/2026 | 23/7/2026 | Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Backdropcms Salesforce ModuleAI | 12/5/2026 | 17/6/2026 | The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks. | |
| Aplazada | Alta (8.1) | 1.1% | — | Drag AND Drop File Upload FOR Contact Form 7AI | 24/4/2026 | 17/6/2026 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than… | |
| Analizada | Media (6.5) | 0.39% | — | Raindrop | 22/4/2026 | 17/6/2026 | Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request. | |
| Analizada | Alta (7.5) | 0.53% | — | Freedom Securedrop-client | 18/4/2026 | 17/6/2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper filename validation in… | |
| Aplazada | Alta (8.1) | 3.5% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 17/4/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension… | |
| Aplazada | Alta (7.5) | 0.59% | — | WP Drag AND Drop File UploadAI | 17/4/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without… | |
| Analizada | Media (5.3) | 0.27% | — | Roastslav Quickdrop | 7/4/2026 | 17/6/2026 | QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application allows SVG files to be uploaded via the /api/file/upload-chunk endpoint. An attacker can upload a specially crafted SVG file containing a JavaScript payload. When any… | |
| Pendiente de análisis | Alta (8.8) | 2.5% | — | Digitalocean Droplet AgentAI | 23/3/2026 | 17/6/2026 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without… | |
| Modificada | Media (6.3) | 0.45% | — | Arekinath EsamlDropbox EsamlHandnot2 EsamlJump-app Esaml | 23/3/2026 | 24/7/2026 | XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2… | |
| Aplazada | Baja (1.7) | 0.19% | — | MKJ DropbearAI | 8/3/2026 | 17/6/2026 | A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high… | |
| Aplazada | Alta (8.1) | 0.95% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 5/3/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Aplazada | Alta (7.7) | 0.36% | — | Murtaza Bhurgri WOO File DropzoneAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone allows Path Traversal.This issue affects Woo File Dropzone: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.4) | 0.38% | — | DropbearAI | 12/2/2026 | 17/6/2026 | A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent… | |
| Analizada | Media (5.3) | 0.23% | — | Metadrop Group Invite | 4/2/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This issue affects Group invite: from 0.0.0 before 2.3.9, from 3.0.0 before 3.0.4, from 4.0.0 before 4.0.4. | |
| Aplazada | Alta (8.2) | 0.69% | — | Ziroom Zhome A0101AIDropbear SSHAI | 3/2/2026 | 17/6/2026 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered… | |
| Aplazada | Media (4.3) | 0.14% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurvey` AJAX action. This… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX action. This makes it… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag AND Drop Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to create surveys via a… | |
| Analizada | Alta (7.4) | 0.22% | — | Codedropz Contact Form 7 | 15/1/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Media (6.1) | 0.37% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 7/1/2026 | 30/9/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (4.3) | 0.24% | — | Contact Form 7 Drag AND Drop Template BuilderAI | 12/12/2025 | 17/6/2026 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post duplication due to a missing capability check on the 'rednumber_duplicate' function in all versions up to, and including, 6.3.3. This makes it possible for authenticated attackers, with Subscriber-level… |