Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.58% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Brainstormforce Convert PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | |
| Pendiente de análisis | Baja (2.3) | 0.32% | — | Snomed International SnowstormAI | 4/8/2026 | 26/8/2026 | SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3. | |
| Aplazada | Media (6.4) | 0.36% | — | Brainstormforce SureformsAI | 1/8/2026 | 12/8/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.37% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 30/7/2026 | 30/7/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Phpstorm | 23/7/2026 | 28/7/2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | |
| Analizada | Alta (7.8) | 0.18% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | |
| Analizada | Alta (8.4) | 0.19% | — | Jetbrains Webstorm | 23/7/2026 | 28/7/2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | |
| Aplazada | Media (6.4) | 0.42% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 22/7/2026 | 22/7/2026 | The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.9) | 0.29% | — | Brainstormforce SureformsAI | 14/7/2026 | 14/7/2026 | The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Brainstormforce SuredashAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Stormshield Network SecurityAI | 2/7/2026 | 2/7/2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Stormshield Network SecurityAI | 1/7/2026 | 1/7/2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain… | |
| Aplazada | Crítica (9.3) | 0.80% | — | Brainstormforce Ultimate Addons FOR Beaver BuilderAI | 20/6/2026 | 29/9/2026 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a… | |
| Aplazada | Alta (8.5) | 0.36% | — | Brainstormforce SuredashAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0. | |
| Aplazada | Media (5.3) | 0.30% | — | Stormshield Network SecurityAI | 1/6/2026 | 22/7/2026 | A vulnerability was discovered on Stormshield Network Security It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page… | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce Presto PlayerAI | 19/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3. | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce SpectraAIBrainstormforce Ultimate-addons-for-gutenbergAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22. | |
| Aplazada | Alta (7.3) | 0.30% | — | Brainstormforce Sureforms PROAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. | |
| Analizada | Media (6.5) | 0.45% | — | Apache Storm | 27/4/2026 | 17/6/2026 | Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a… | |
| Analizada | Media (4.8) | 0.28% | — | Apache Storm Prometheus Reporter | 27/4/2026 | 17/6/2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to… |