Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
21.063 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.17% | — | Apple IpadosApple Iphone OSApple TvosApple Visionos+1 | 14/9/2026 | 18/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. | |
| Analizada | Alta (8.2) | 0.14% | — | Apple IpadosApple Iphone OSApple Macos | 14/9/2026 | 18/9/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox. | |
| Modificada | Alta (8.8) | 0.48% | — | Apple Macos | 14/9/2026 | 18/9/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious afpfs server may lead to kernel memory corruption. | |
| Analizada | Alta (7.1) | 0.16% | — | Apple Macos | 14/9/2026 | 18/9/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory. | |
| Analizada | Media (4.6) | 0.22% | — | Apple IpadosApple Iphone OS | 14/9/2026 | 18/9/2026 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 18/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel… | |
| Analizada | Media (4.3) | 0.42% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 14/9/2026 | 18/9/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination. | |
| Analizada | Media (6.1) | 0.20% | — | Apple Macos | 14/9/2026 | 18/9/2026 | A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device. | |
| Aplazada | Media (5.1) | 0.34% | — | Yamap - Social Trekking GPS APPAI | 14/9/2026 | 16/9/2026 | The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites. | |
| Aplazada | Alta (8.4) | 0.18% | — | Rakuten Kobo Desktop ApplicationAI | 14/9/2026 | 16/9/2026 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. | |
| Aplazada | Media (6.1) | 0.19% | — | FrappeAI | 14/9/2026 | 16/9/2026 | Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages. | |
| Aplazada | Baja (2.9) | 0.28% | — | Andreashappe CochiseAIAsyncsshAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a… | |
| Aplazada | Media (5.3) | 0.34% | — | Contact Form TO Chat AppsAI | 13/9/2026 | 14/9/2026 | The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps |… | |
| Pendiente de análisis | Alta (8.7) | 0.63% | — | Xerial Snappy-javaAI | 12/9/2026 | 24/9/2026 | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past… | |
| Aplazada | Media (6.4) | 0.24% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of… | |
| Aplazada | Media (5.3) | 0.32% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking… | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method… | |
| Aplazada | Media (6.5) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner… | |
| Aplazada | Media (5.5) | 0.32% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC… | |
| Aplazada | Alta (7.2) | 0.46% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing… | |
| Aplazada | Alta (7.2) | 0.46% | — | Ameliabooking Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address… | |
| Aplazada | Media (5.3) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an… | |
| Aplazada | Media (5.1) | 0.30% | — | Qlomodules QloappAI | 12/9/2026 | 23/9/2026 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's… | |
| Pendiente de análisis | Media (4.4) | 0.15% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (4.8) | 0.14% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. |