Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.38% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is… | |
| Aplazada | Baja (2) | 0.33% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.40% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.37% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely.… | |
| Aplazada | Baja (2) | 0.45% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Baja (2) | 0.43% | — | Webkul BagistoAI | 14/8/2026 | 18/8/2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (6.1) | 0.95% | — | Perl PDF WebkitAI | 13/8/2026 | 26/8/2026 | PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for reads each entry of the stylesheets list, by assigning the path to a local @ARGV… | |
| Aplazada | Crítica (9.8) | 0.73% | — | PDF WebkitAI | 13/8/2026 | 26/8/2026 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> element in the document head through _pdf_webkit_meta_tags and turns each one into a… | |
| Aplazada | Alta (8.7) | 0.50% | — | Webkul Krayin CRMAI | 3/8/2026 | 9/9/2026 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw()… | |
| Aplazada | Media (5.1) | 0.36% | — | Webkul BagistoAI | 9/7/2026 | 14/7/2026 | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php… | |
| Aplazada | Alta (8.5) | 0.36% | — | Inet WebkitAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in iNET Webkit 1.2.4 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Webkul Ajax Quiz | 19/6/2026 | 19/8/2026 | Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract… | |
| Aplazada | Media (4.8) | 0.30% | — | Webkul QloappsAI | 8/6/2026 | 23/7/2026 | QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to… | |
| Aplazada | Alta (8.7) | 1.8% | — | Webkul BagistoAI | 8/6/2026 | 23/7/2026 | This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended… | |
| Aplazada | Alta (8.2) | 0.27% | — | Webkul QloappsAI | 2/6/2026 | 22/7/2026 | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the… | |
| Aplazada | Media (5.4) | 0.30% | — | Webkul Krayin CRMAI | 7/5/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | WebkitgtkAIWPE WebkitAI | 23/4/2026 | 17/6/2026 | An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal… | |
| Aplazada | Baja (2) | 0.33% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.8) | 0.84% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. |