Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.34% | — | Prestashop BlockwishlistAI | 16/9/2026 | 22/9/2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'… | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop PsgdprAI | 16/9/2026 | 22/9/2026 | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs. | |
| Aplazada | Alta (8.4) | 0.62% | — | Zope RestrictedpythonAI | 16/9/2026 | 16/9/2026 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter… | |
| Pendiente de análisis | Media (5.1) | 0.25% | — | Arista EOSAIOpenconfig GnmiAIOpenconfig GnsiAIOpenconfig RestconfAI+1 | 16/9/2026 | 16/9/2026 | On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming… | |
| Aplazada | Media (6.9) | 0.38% | — | Miniorange JWT Authentication FOR WP Rest ApisAI | 15/9/2026 | 24/9/2026 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.… | |
| Aplazada | Alta (8.6) | 0.38% | — | Alior Bank RatyAIPrestashopAI | 14/9/2026 | 18/9/2026 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The module inserts values of the POST parameters "alior_product_promotion",… | |
| Aplazada | Alta (8.6) | 0.24% | — | Alior Bank RatyAIPrestashopAI | 14/9/2026 | 18/9/2026 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitization or validation. An attacker with access to the product or category add/edit… | |
| Aplazada | Crítica (9.2) | 0.40% | — | Hiperdino Rest APIAI | 14/9/2026 | 18/9/2026 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone… | |
| Aplazada | Media (6.9) | 0.77% | — | Node-restifyAI | 13/9/2026 | 21/9/2026 | A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.1) | 0.21% | — | Socketdev Socket-registry-firewallAIOpenrestyAI | 12/9/2026 | 22/9/2026 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and… | |
| Aplazada | Alta (8.8) | 0.51% | — | BE Rest EndpointsAI | 12/9/2026 | 14/9/2026 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpeverest Everest FormsAI | 11/9/2026 | 11/9/2026 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Zhbackup Backup Restore MigrationAI | 10/9/2026 | 10/9/2026 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | |
| Aplazada | Crítica (9.3) | 0.37% | — | CapgoAISupabaseAISupabase PostgrestAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route… | |
| Aplazada | Media (6.9) | 0.54% | — | PrestashopAI | 7/9/2026 | 8/9/2026 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address… | |
| Pendiente de análisis | Alta (8) | 1.7% | — | Spatie Laravel-backup-restoreAISpatie Laravel-backupAI | 4/9/2026 | 10/9/2026 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4. | |
| Aplazada | Media (5.3) | 0.16% | — | Restaurant Menu AND Food OrderingAI | 4/9/2026 | 8/9/2026 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | |
| Aplazada | Media (5.3) | 0.35% | — | Dev.institute Restrict User AccessAI | 2/9/2026 | 3/9/2026 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | Redhat ResteasyAI | 31/8/2026 | 2/10/2026 | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or… | |
| Aplazada | Alta (8.6) | 0.28% | — | Rest RoutesAI | 29/8/2026 | 31/8/2026 | The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Media (5.3) | 0.41% | — | Wpeverest Everest FormsAI | 28/8/2026 | 28/8/2026 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are… | |
| Aplazada | Media (5.4) | 0.30% | — | Prestashop XipblogAIPrestashopAI | 28/8/2026 | 9/9/2026 | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output escaping, resulting in Stored Cross-Site… | |
| Analizada | Alta (7.1) | 0.35% | — | Vmware Spring Data Rest | 27/8/2026 | 2/9/2026 | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier | |
| Analizada | Media (4.3) | 0.31% | — | Vmware Spring Data Rest | 27/8/2026 | 4/9/2026 | Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier | |
| Aplazada | Alta (7.7) | 0.22% | — | Compliance-trestle TrestleAI | 26/8/2026 | 9/9/2026 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without… |