Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
40.028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.38% | 💥 PoC | Joomlaboat Youtube GalleryAI | 26/9/2026 | 29/9/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| Aplazada | Crítica (9.3) | 0.21% | — | FroxlorAI | 26/9/2026 | 26/9/2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O'])… | |
| Aplazada | Crítica (9.4) | 0.39% | — | FroxlorAI | 26/9/2026 | 28/9/2026 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the… | |
| Aplazada | Crítica (9.4) | 0.55% | — | FroxlorAI | 26/9/2026 | 26/9/2026 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php… | |
| Pendiente de análisis | Crítica (9.4) | 0.61% | — | KyvernoAI | 26/9/2026 | 28/9/2026 | kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal… | |
| Aplazada | Crítica (9.2) | 0.33% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attackers can gain complete account access including chatflows,… | |
| Aplazada | Crítica (9.2) | 0.37% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored… | |
| Aplazada | Crítica (9.8) | 0.41% | 💥 PoC | Afrfq Request A Quote FOR WoocommerceAI | 26/9/2026 | 28/9/2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied… | |
| Aplazada | Crítica (9) | 0.17% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to… | |
| Pendiente de análisis | Crítica (10) | 0.95% | 💥 PoC | Wikimedia External DataAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7. | |
| Aplazada | Crítica (9.1) | 0.29% | — | ZoraxyAI | 25/9/2026 | 30/9/2026 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. | |
| Aplazada | Crítica (9.2) | 0.58% | — | GestsupAI | 25/9/2026 | 30/9/2026 | GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket… | |
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 30/9/2026 | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number. | |
| Pendiente de análisis | Crítica (9.3) | 0.29% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 28/9/2026 | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as… | |
| Aplazada | Crítica (9.1) | 0.36% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that… | |
| Aplazada | Crítica (9.4) | 0.34% | — | GlpiAI | 25/9/2026 | 29/9/2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious… | |
| Aplazada | Crítica (9.8) | 0.27% | — | Friendsofflarum OauthAI | 25/9/2026 | 30/9/2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When… | |
| Aplazada | Crítica (9.1) | 0.30% | — | PiwigoAI | 25/9/2026 | 29/9/2026 | Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the… | |
| Aplazada | Crítica (9.1) | 0.53% | 💥 PoC | PiwigoAI | 25/9/2026 | 28/9/2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload… | |
| Aplazada | Crítica (9.1) | 0.45% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the… | |
| Pendiente de análisis | Crítica (9.3) | 0.23% | — | ZimbraAI | 25/9/2026 | 29/9/2026 | An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim. | |
| Pendiente de análisis | Crítica (9.8) | 0.96% | — | Onlyoffice Document EditingAI | 25/9/2026 | 29/9/2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | |
| Pendiente de análisis | Crítica (9.3) | 0.23% | — | ZimbraAI | 25/9/2026 | 29/9/2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. | |
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | ZimbraAI | 25/9/2026 | 29/9/2026 | An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. |