Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
9646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.21% | — | Villatheme WOO Product BuilderAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.23% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (8.7) | 0.18% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Alta (7.2) | 0.30% | — | Siteorigin Page BuilderAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Boldgrid Post AND Page BuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | Visualcomposer Visual Composer Website BuilderAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Themify BuilderAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Profile BuilderAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quiz CATAI | 30/9/2026 | 30/9/2026 | Author SQL Injection in Quiz Cat <= 3.1.1 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Squirrly SEOAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 30/9/2026 | 30/9/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Media (6.9) | 0.17% | — | Quick.cartAI | 29/9/2026 | 30/9/2026 | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it… | |
| Pendiente de análisis | Alta (8.5) | 0.25% | — | Hitachienergy Asset SuiteAI | 29/9/2026 | 29/9/2026 | Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. | |
| Pendiente de análisis | Media (5.1) | 0.25% | — | Hitachienergy Asset SuiteAI | 29/9/2026 | 29/9/2026 | Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production… | |
| Aplazada | Media (5.5) | 0.28% | — | RebuildAI | 29/9/2026 | 1/10/2026 | A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be… |