Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 7/9/2026 | 9/9/2026 | A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.48% | — | Sourcecodester Syllabus-aligned Learning Management & Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2.1) | 0.45% | — | Projectworlds Online Examination SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Media (6.7) | 0.18% | — | Keyence XG VisionterminalAIKeyence Xg-x VisionterminalAI | 3/9/2026 | 15/9/2026 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed. | |
| Aplazada | Media (5.3) | 0.29% | — | Incsub ForminatorAI | 28/8/2026 | 28/8/2026 | Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions. | |
| Aplazada | Alta (7.2) | 0.45% | — | Incsub ForminatorAI | 28/8/2026 | 28/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Baja (3.7) | 0.15% | — | Incsub ForminatorAI | 26/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it. | |
| Aplazada | Alta (7.2) | 0.35% | — | Wpmudev ForminatorAI | 25/8/2026 | 26/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.44% | — | Wpmudev ForminatorAI | 25/8/2026 | 26/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.6) | 0.36% | — | Wpmudev Forminator FormsAI | 22/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it. | |
| Aplazada | Alta (7.2) | 0.66% | — | Incsub ForminatorAI | 22/8/2026 | 26/8/2026 | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Incsub ForminatorAI | 20/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | |
| Aplazada | Crítica (9.8) | 6.1% | 💥 PoC | Incsub ForminatorAI | 18/8/2026 | 20/8/2026 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed… | |
| Aplazada | Media (5.3) | 0.22% | — | Sourcecodester Onlne Examination & Learning Management SystemAI | 18/8/2026 | 20/8/2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | |
| Aplazada | Media (5.3) | 0.29% | — | Next TerminalAI | 17/8/2026 | 24/9/2026 | Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with arbitrary asset identifiers to retrieve asset information including display names,… | |
| Aplazada | Media (5.3) | 0.52% | — | Wpmudev ForminatorAI | 16/8/2026 | 20/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.3) | 0.13% | — | Northbridge LuminalshineAI | 13/8/2026 | 9/9/2026 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` lives at `C:\ProgramData\LuminalShine\config\apps.json` and is created by the `SYSTEM` service. Under Windows' default… | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.35% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. | |
| Aplazada | Alta (7.1) | 0.25% | — | Incsub ForminatorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Incsub ForminatorAI | 6/8/2026 | 12/8/2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | |
| Aplazada | Alta (7.2) | 0.48% | — | Wpdesk ForminatorAI | 6/8/2026 | 12/8/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Pendiente de análisis | Media (5) | 0.35% | — | Cisco Terminal Service AgentAI | 5/8/2026 | 6/8/2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least… | |
| Analizada | Media (5.4) | 0.64% | — | Apache Mina Sshd | 20/7/2026 | 27/7/2026 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the… |