Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

6563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.41%—StoatchatAI16/7/202616/7/2026
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata…
AplazadaMedia (6.9)0.45%—StoatchatAI16/7/202618/7/2026
stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.
AplazadaAlta (7.6)0.48%—StoatchatAI16/7/20266/10/2026
Las versiones de stoatchat (delta/Revolt) desde 20241213-1 anteriores a 20250210-1 permiten a los usuarios con solo el permiso ViewChannel (lectura) en un canal recuperar los webhooks de ese canal, incluyendo sus tokens, porque el endpoint de recuperación de webhooks verificaba ViewChannel en lugar de ManageWebhooks.…
AplazadaAlta (8.7)0.67%—StoatchatAI16/7/20266/10/2026
Las versiones de stoatchat (delta) anteriores a 20250210-1 (0.8.2) contienen un error lógico en la ruta de consulta de mensajes. Al recuperar mensajes 'cercanos' a otro mensaje, la consulta de la base de datos puede recibir un límite de mensajes de cero, lo que la base de datos interpreta como 'sin límite'. Un…
AnalizadaCrítica (9.6)0.48%—Broadcom Spring Authorization Server16/7/20264/9/2026
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.
AplazadaAlta (7.2)0.43%—RPB ChessboardAI16/7/202618/7/2026
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AnalizadaAlta (8.1)0.56%—Redhat Build OF Keycloak16/7/20269/8/2026
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control…
AplazadaAlta (7.2)0.50%—KanboardAI15/7/202615/7/2026
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential…
AnalizadaAlta (7.6)0.41%—Better-auth/oauth-providerBetter-auth Better Auth15/7/202621/7/2026
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to…
AnalizadaAlta (8.1)0.42%—Better-auth/oauth-providerBetter-auth Better Auth15/7/202621/7/2026
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests…
Pendiente de análisisMedia (5.8)0.65%—Amazon AWS Load Balancer ControllerAI14/7/202615/7/2026
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should…
AplazadaBaja (2.9)0.46%—Waooai WaoowaooAI13/7/202615/7/2026
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack…
AplazadaMedia (5.5)0.69%—Waooai WaoowaooAI13/7/202613/7/2026
A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the component Internal Task Header Handler. This manipulation of the…
AplazadaMedia (5.5)0.41%—Jinher OAAI13/7/202614/7/2026
A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. This manipulation of the argument httpOID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was…
AplazadaBaja (2)0.33%—Amtt Hotel Broadband Operation SystemAI12/7/202613/7/2026
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The…
ModificadaCrítica (9)0.54%—Phoca Download11/7/202619/8/2026
Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
AplazadaMedia (4.3)0.41%—MUX Video UploaderAI11/7/202613/7/2026
The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API…
AplazadaMedia (4.4)0.41%—Lockme Oauth2 Calendars IntegrationAI11/7/202613/7/2026
The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,…
AplazadaMedia (6.4)0.35%—Starboard Suite Reservation CalendarsAI11/7/202629/9/2026
El plugin Starboard Suite Reservation Calendars para WordPress es vulnerable a cross-site scripting almacenado a través de atributos de shortcode en el shortcode [starboard-suite-lightbox] en todas las versiones hasta la 3.1.4, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto…
AplazadaCrítica (9.8)0.73%—Miniorange Oauth Single Sign ON - SSOAI10/7/202621/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
AnalizadaMedia (5.3)0.41%—Broadcom Rabbitmq Server10/7/202613/7/2026
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read…
AnalizadaAlta (7.5)0.55%—Broadcom Rabbitmq Server10/7/202613/7/2026
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker…
AnalizadaAlta (8.7)2.8%💥 ExploitBroadcom Rabbitmq Server10/7/202629/7/2026
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and…
AnalizadaMedia (4.9)0.35%—Broadcom Rabbitmq Server10/7/202613/7/2026
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user…
AnalizadaAlta (7)0.35%—Broadcom Rabbitmq Server10/7/202613/7/2026
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow.…