Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

8600 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.63%—Fluentforms Fluent FormsAI31/7/202612/8/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for…
AplazadaAlta (8.3)0.18%—Softtr Information Technology Trade LTD E-commerce PackAI30/7/202631/7/2026
Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaBaja (3.7)0.25%—Bitapps BIT FormAI30/7/202630/7/2026
The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.
AplazadaMedia (6.1)0.25%—Fluentforms Fluent FormsAI30/7/202630/7/2026
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the…
AnalizadaCrítica (10)0.81%💥 PoCAimy-extensions Aimy Captcha-less Form Guard29/7/20265/8/2026
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
AplazadaAlta (7.2)0.53%—Fluentcrm Fluent FormsAI29/7/202630/7/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.3)0.34%—Survey Form BlockAI29/7/202630/7/2026
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey…
AplazadaMedia (6.4)0.33%—Itpathsolutions Contact Form TO ANY APIAI29/7/202630/7/2026
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaCrítica (10)0.46%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in…
AplazadaAlta (8.9)0.36%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed…
AplazadaAlta (8.6)0.39%—Terraform-mcp-serverAI28/7/202630/7/2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This…
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins28/7/20265/8/2026
Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaCrítica (10)0.77%—Balbooa FormsAI28/7/202628/7/2026
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
Pendiente de análisisMedia (4.3)0.24%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI28/7/202628/7/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their…
AplazadaMedia (4.3)0.39%—Advancedformintegration Advanced Form IntegrationAI28/7/202628/7/2026
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.25%—Database FOR Contact Form 7 Wpforms Elementor FormsAI28/7/202628/7/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.1)0.25%—Kali FormsAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
AplazadaAlta (7.2)0.58%💥 ExploitFormcraftAI27/7/202628/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
AplazadaAlta (7.1)0.25%—Themefic Ultimate Addons FOR Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
AplazadaAlta (7.1)0.25%—Contact Form 7AI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
AplazadaAlta (7.5)0.35%—Post MY CF7 FormAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
AplazadaMedia (4.7)0.29%—Contact Form 7AI27/7/202627/7/2026
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after the checkout flow.
AplazadaAlta (8.8)0.55%—Fluent Forms PRO ADD ON PackAI26/7/202627/7/2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of…
AplazadaAlta (8.1)2.5%💥 ExploitWpforms PROAI25/7/202627/7/2026
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not…
AplazadaMedia (6.1)0.25%—Polen Media Software AND Information Services Website TemplateAI24/7/202624/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.