Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 49 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Metagauss ProfilegridAI | 2/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. | |
| Aplazada | Alta (7.5) | 0.41% | — | Metagauss ProfilegridAI | 30/7/2026 | 30/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists,… | |
| Analizada | Alta (7.3) | 0.19% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site. | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins. | |
| Analizada | Crítica (9.2) | 0.55% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. | |
| Analizada | Media (6.1) | 0.27% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | |
| Analizada | Media (5.3) | 0.35% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | |
| Analizada | Media (5.3) | 0.34% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | |
| Analizada | Crítica (9.2) | 0.50% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | |
| Analizada | Crítica (9.2) | 0.44% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories. | |
| Analizada | Crítica (9.4) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker. | |
| Analizada | Crítica (10) | 0.52% | — | Balbooa Gridbox | 29/7/2026 | 5/8/2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions. | |
| Aplazada | Baja (3.8) | 0.26% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings. | |
| Aplazada | Media (5.4) | 0.23% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads. | |
| Aplazada | Media (6.5) | 0.27% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made. | |
| Aplazada | Media (6.4) | 0.33% | — | Postx Post Grid Gutenberg BlocksAI | 24/7/2026 | 24/7/2026 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.33% | — | Grid List View FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Crítica (9.4) | 0.57% | — | Balbooa GridboxAI | 20/7/2026 | 23/7/2026 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Aplazada | Alta (7.5) | 0.48% | — | Metagauss ProfilegridAI | 13/7/2026 | 13/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6. | |
| Aplazada | Alta (7.5) | 2.9% | — | Boldgrid W3 Total CacheAI | 11/7/2026 | 14/7/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation… | |
| Aplazada | Alta (8.8) | 0.44% | — | Wpgridbuilder WP Grid BuilderAI | 11/7/2026 | 13/7/2026 | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… |