Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6555 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres… | |
| Pendiente de análisis | Crítica (9.3) | — | — | Payloadcms PayloadAIPayloadcms Plugin Import ExportAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can… | |
| Pendiente de análisis | Alta (8.6) | — | — | Payloadcms Plugin MCPAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the intended account, enabling privilege escalation through account takeover. This issue is fixed in version 3.88.0. | |
| Pendiente de análisis | Media (6.9) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected field as the sort parameter can infer limited information about field values the… | |
| Pendiente de análisis | Media (5.7) | — | — | Payloadcms PayloadAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password hashing, reducing the computational effort required to test recovered password… | |
| Aplazada | Media (5.3) | — | — | Webkul QloappsAI | 6/10/2026 | 6/10/2026 | QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive… | |
| Aplazada | Alta (8.2) | 0.11% | — | Danielberkompas CloakAI | 6/10/2026 | 6/10/2026 | Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key… | |
| Aplazada | Media (6.3) | 0.26% | — | Danielberkompas Cloak EctoAIDanielberkompas CloakAI | 6/10/2026 | 6/10/2026 | Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2… | |
| Aplazada | Alta (7.8) | 0.30% | — | EloanappAI | 6/10/2026 | 6/10/2026 | SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover… | |
| Aplazada | Alta (7.5) | 0.26% | — | Easydigitaldownloads Easy Digital DownloadsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. | |
| Pendiente de análisis | Media (5.4) | 0.19% | — | KeycloakAI | 6/10/2026 | 6/10/2026 | A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints | |
| Aplazada | Alta (7.5) | 0.27% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint | |
| Aplazada | Baja (2.1) | 0.22% | — | Zoneland O2oaAI | 5/10/2026 | 6/10/2026 | A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched… | |
| Aplazada | Crítica (9.8) | 0.39% | — | GouguoaAI | 5/10/2026 | 6/10/2026 | GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | |
| Aplazada | Media (5.9) | 0.20% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. | |
| Aplazada | Media (5.9) | 0.29% | — | Wedevs File UploadsAI | 5/10/2026 | 6/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly,… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | KeycloakAI | 5/10/2026 | 6/10/2026 | A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that… | |
| Pendiente de análisis | Media (5.7) | 0.20% | — | KeycloakAI | 5/10/2026 | 6/10/2026 | A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a… | |
| Pendiente de análisis | Media (4) | 0.12% | — | KeycloakAI | 5/10/2026 | 6/10/2026 | A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a… | |
| Aplazada | Media (6.3) | 0.22% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass… | |
| Aplazada | Alta (7.1) | 0.31% | — | LaradashboardAI | 3/10/2026 | 6/10/2026 | LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail… | |
| Aplazada | Media (5.3) | 0.26% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving… | |
| Aplazada | Media (6.9) | 0.41% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for… | |
| Aplazada | Alta (8.6) | 0.49% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade… |