Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 49 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

634 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Metagauss ProfilegridAI2/8/202626/8/2026
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
AplazadaAlta (7.5)0.41%—Metagauss ProfilegridAI30/7/202630/7/2026
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists,…
AnalizadaAlta (7.3)0.19%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
AnalizadaCrítica (9.2)0.55%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
AnalizadaMedia (6.1)0.27%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
AnalizadaMedia (5.3)0.35%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
AnalizadaMedia (5.3)0.34%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
AnalizadaCrítica (9.2)0.50%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
AnalizadaCrítica (9.2)0.44%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
AnalizadaCrítica (9.4)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
AnalizadaCrítica (10)0.52%—Balbooa Gridbox29/7/20265/8/2026
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
AplazadaBaja (3.8)0.26%—Metagauss ProfilegridAI24/7/202624/7/2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.
AplazadaMedia (5.4)0.23%—Metagauss ProfilegridAI24/7/202624/7/2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.
AplazadaMedia (6.5)0.27%—Metagauss ProfilegridAI24/7/202624/7/2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.
AplazadaMedia (6.4)0.33%—Postx Post Grid Gutenberg BlocksAI24/7/202624/7/2026
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.33%—Grid List View FOR WoocommerceAI23/7/202623/7/2026
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaCrítica (9.4)0.57%—Balbooa GridboxAI20/7/202623/7/2026
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
ModificadaMedia (5.4)0.39%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on17/7/202616/9/2026
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that…
ModificadaBaja (2.7)0.35%—Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on16/7/202616/9/2026
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to…
AplazadaAlta (7.5)0.48%—Metagauss ProfilegridAI13/7/202613/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.
AplazadaAlta (7.5)2.9%—Boldgrid W3 Total CacheAI11/7/202614/7/2026
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation…
AplazadaAlta (8.8)0.44%—Wpgridbuilder WP Grid BuilderAI11/7/202613/7/2026
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.34%—Profilegrid Memberships AND User Profiles FOR WoocommerceAI9/7/20269/7/2026
The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()…