Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
8598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.21% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (6.5) | 0.44% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (5.4) | 0.23% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Analizada | Baja (3.3) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached… | |
| Modificada | Media (4.4) | 0.08% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or… | |
| Aplazada | Alta (7.1) | 0.37% | — | Getgrav Grav-plugin-formAI | 3/8/2026 | 31/8/2026 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect… | |
| Modificada | Media (4.4) | 0.14% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with… | |
| Analizada | Media (5.5) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Huggingface TransformersAIHuggingface IdeficsAIHuggingface FlorenceAIHuggingface GemmaAI+2 | 2/8/2026 | 3/9/2026 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames… | |
| Aplazada | Media (6.1) | 0.37% | — | Fluentforms Fluent FormsAI | 1/8/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 1.2% | — | Kaliforms Kali FormsAI | 1/8/2026 | 12/8/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder,… | |
| Aplazada | Alta (8.1) | 0.58% | — | NEX FormsAI | 1/8/2026 | 12/8/2026 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no… | |
| Aplazada | Alta (7.2) | 0.42% | — | Pluginops Mailchimp Subscribe FormAI | 1/8/2026 | 12/8/2026 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.56% | — | Gutena FormsAI | 1/8/2026 | 12/8/2026 | The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (8.1) | 0.38% | — | Login Register FormsAI | 1/8/2026 | 26/8/2026 | The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at… | |
| Aplazada | Crítica (9.1) | 0.90% | — | FormgentAI | 1/8/2026 | 12/8/2026 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware… | |
| Aplazada | Media (4.8) | 0.24% | — | Bitapps BIT FormAI | 1/8/2026 | 29/9/2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the… | |
| Aplazada | Media (6.4) | 0.36% | — | Brainstormforce SureformsAI | 1/8/2026 | 12/8/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.91% | — | Sentence-transformersAI | 31/7/2026 | 9/9/2026 | sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause… | |
| Pendiente de análisis | Alta (8.2) | 0.43% | — | Redhat Ansible Automation PlatformAIRedhat AAP GatewayAI | 31/7/2026 | 4/8/2026 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The… | |
| Aplazada | Media (5.3) | 0.63% | — | Fluentforms Fluent FormsAI | 31/7/2026 | 12/8/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (8.3) | 0.18% | — | Softtr Information Technology Trade LTD E-commerce PackAI | 30/7/2026 | 31/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49. |