Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.28% | — | Interinfo DreammakerAI | 4/9/2026 | 8/9/2026 | DreamMaker, desarrollado por Interinfo, tiene una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) reflejada. Los atacantes remotos autenticados pueden ejecutar código JavaScript arbitrario en el navegador del usuario a través de un sitio web malicioso. | |
| Aplazada | Alta (8.7) | 0.54% | — | Interinfo DreammakerAI | 4/9/2026 | 8/9/2026 | DreamMaker, desarrollado por Interinfo, tiene una vulnerabilidad de inyección SQL. Los atacantes remotos autenticados pueden inyectar comandos SQL arbitrarios para leer, modificar y eliminar el contenido de la base de datos. | |
| Pendiente de análisis | Alta (8.5) | 0.63% | — | Amazon Sagemaker Python SDKAI | 1/9/2026 | 3/9/2026 | El almacenamiento en texto claro de información confidencial en el componente de pipeline de los decoradores @step y @remote en Amazon SageMaker Python SDK anterior a la v3.11.0 y la v2.256.0 podría permitir a un usuario remoto autenticado extraer la clave de firma HMAC de las respuestas de la API DescribePipeline de… | |
| Aplazada | Media (6.4) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 1/9/2026 | 1/9/2026 | El plugin WP Recipe Maker Premium para WordPress es vulnerable a secuencias de comandos en sitios cruzados (XSS) almacenadas a través del shortcode 'wprm-call-to-action' del plugin en todas las versiones hasta la 10.5.0 incluida, debido a un saneamiento insuficiente de la entrada y a un escape insuficiente de la… | |
| Aplazada | Alta (8.3) | 0.26% | — | NetmakerAI | 26/8/2026 | 24/9/2026 | Netmaker deshabilita la verificación de certificados en la conexión con el servidor de correo configurado. El remitente de pro/email/smtp.go asigna una configuración TLS cuyo campo skip-verify se establece en true de forma incondicional, justo debajo de un comentario que indica que el ajuste debería ser false en… | |
| Aplazada | Alta (7.1) | 0.25% | — | 10web Form MakerAI | 20/8/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49. | |
| Aplazada | Media (5.3) | 0.49% | — | 10web Form MakerAI | 15/8/2026 | 20/8/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Html FormhandlerAIPerlAILocale MaketextAI | 13/8/2026 | 8/9/2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the… | |
| Aplazada | Alta (8.1) | 0.39% | — | 10web Form MakerAI | 12/8/2026 | 26/8/2026 | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection. | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | SssdAIRedhat Insights-coreAIClusterlabs PacemakerAI | 11/8/2026 | 14/8/2026 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ays-pro Survey MakerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Code-atlantic Popup MakerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | |
| Analizada | Media (4.9) | 0.49% | — | Claris Filemaker Server | 9/7/2026 | 10/7/2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. | |
| Aplazada | Alta (7.2) | 1.2% | — | Code-atlantic Popup MakerAI | 9/7/2026 | 9/7/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ays-pro Survey MakerAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. | |
| Aplazada | Alta (8.4) | 1.1% | — | Gotcha Gotcha Games INC RPG Maker MVAIGotcha Gotcha Games INC RPG Maker MZAI | 30/6/2026 | 30/6/2026 | RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed. | |
| Aplazada | Media (4.9) | 0.34% | — | 10web Form MakerAI | 18/6/2026 | 18/6/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (4.9) | 0.34% | — | 10web Form MakerAI | 18/6/2026 | 18/6/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Alta (8.8) | 0.48% | — | Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI | 17/6/2026 | 6/10/2026 | Inyección de objetos PHP para suscriptores en el tema de WordPress Entrepreneur - Booking for Small Businesses versiones menor o igual a 3.1.3. | |
| Pendiente de análisis | Alta (8.6) | 0.56% | — | Clusterlabs PacemakerAI | 16/6/2026 | 21/8/2026 | A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in… | |
| Aplazada | Crítica (9.3) | 0.40% | — | 10web Form MakerAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | |
| Aplazada | Media (6.9) | 0.39% | — | Interinfo DreammakerAI | 29/5/2026 | 21/7/2026 | DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de salto de ruta, permitiendo a atacantes remotos no autenticados leer nombres de archivos bajo una ruta arbitraria explotando una vulnerabilidad de salto de ruta absoluto. | |
| Aplazada | Media (6.9) | 0.35% | — | Interinfo DreammakerAI | 29/5/2026 | 21/7/2026 | DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de lectura arbitraria de archivos, permitiendo a atacantes locales privilegiados explotar el salto de ruta relativo para descargar archivos de sistema arbitrarios. | |
| Aplazada | Alta (8.7) | 0.35% | — | Interinfo DreammakerAI | 29/5/2026 | 21/7/2026 | DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de lectura arbitraria de archivos, permitiendo a atacantes locales no autenticados explotar el salto de ruta relativo para descargar archivos arbitrarios del sistema. |