Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
488 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.31% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the forgotten-password path in… | |
| Aplazada | Alta (7.1) | 0.22% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates… | |
| Aplazada | Media (6.5) | 0.22% | — | Dynamiapps Frontend AdminAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Crítica (9.8) | 0.84% | — | Dynamiapps Frontend AdminAI | 16/8/2026 | 20/8/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the… | |
| Aplazada | Alta (7.2) | 0.38% | — | Camaleon AttackAICamaleon Front CacheAICamaleon Cama Meta TAGAICamaleon Cama Contact FormAI+1 | 12/8/2026 | 26/8/2026 | CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime… | |
| Aplazada | Alta (8.8) | 0.59% | — | Dynamiapps Frontend AdminAI | 11/8/2026 | 12/8/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dynamiapps Frontend AdminAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Crítica (9.3) | 0.73% | — | FrontmcpAIZODAI | 6/8/2026 | 10/9/2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force… | |
| Aplazada | Media (5.4) | 0.13% | — | Najeebmedia Frontend File ManagerAI | 2/8/2026 | 26/8/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,… | |
| Aplazada | Alta (8.8) | 0.45% | — | Dynamiapps Frontend AdminAI | 31/7/2026 | 26/8/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output… | |
| Aplazada | Media (6.5) | 0.30% | — | Dynamiapps Frontend AdminAI | 30/7/2026 | 30/7/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs User FrontendAI | 27/7/2026 | 27/7/2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments such as guest uploads… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft Enterprise FIN Staffing Front Office Brazil | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing… | |
| Analizada | Alta (7.5) | 0.35% | — | Oracle Peoplesoft Enterprise FIN Staffing Front Office | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office product of Oracle PeopleSoft (component: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Aplazada | Media (5.3) | 0.42% | — | Wedevs User FrontendAI | 9/7/2026 | 9/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' parameter due to missing validation on a user controlled key. This makes… | |
| Aplazada | Media (5.3) | 0.31% | — | User FrontendAI | 8/7/2026 | 8/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This… | |
| Aplazada | Alta (8.7) | 0.39% | — | Najeebmedia Frontend File ManagerAI | 7/7/2026 | 7/7/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the… | |
| Analizada | Alta (7.9) | 0.63% | — | Amazon Cloudfront | 29/6/2026 | 1/7/2026 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No… | |
| Aplazada | Media (6.5) | 0.33% | — | Wedevs WP User FrontendAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | |
| Aplazada | Alta (7.2) | 0.47% | — | FrontaccountingAI | 29/6/2026 | 1/7/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attackers with SA_GLANALYTIC permission can inject arbitrary SQL by supplying a closing parenthesis… | |
| Aplazada | Alta (7.2) | 0.47% | — | FrontaccountingAI | 29/6/2026 | 29/6/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malicious code into the PARAM_2 and PARAM_3 POST parameters. Attackers can exploit time-based blind SQL… | |
| Aplazada | Alta (7.1) | 0.23% | — | FrontaccountingAI | 29/6/2026 | 29/6/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized… | |
| Aplazada | Alta (8.7) | 0.98% | — | FrontaccountingAI | 29/6/2026 | 30/6/2026 | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files… | |
| Aplazada | Alta (8.1) | 0.60% | — | Najeebmedia Frontend File ManagerAI | 28/6/2026 | 29/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase… | |
| Aplazada | Media (6.5) | 0.47% | — | Najeebmedia Frontend File ManagerAI | 26/6/2026 | 26/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin… |