Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

6569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.28%—Paloaltonetworks Pan-os9/7/202611/8/2026
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by…
ModificadaBaja (1.7)0.34%—Paloaltonetworks Pan-os9/7/202611/8/2026
An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability.
ModificadaBaja (1.3)0.75%—Paloaltonetworks Pan-os9/7/202611/8/2026
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk…
AplazadaMedia (5.4)0.23%—Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitBalbooa Forms9/7/202624/7/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AplazadaMedia (6.4)0.35%—Download ManagerAI9/7/20269/7/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.1)0.38%—Mang Board WPAI9/7/20269/7/2026
The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaAlta (7.2)0.83%—Paloaltonetworks Pan-os8/7/202611/8/2026
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The…
AplazadaAlta (7.1)0.39%—GumroadAI8/7/202610/7/2026
Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation. Attackers…
AplazadaBaja (2.1)0.29%—Flask-dashboard Flask-monitoringdashboardAI8/7/20268/7/2026
A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was…
AplazadaCrítica (9.8)0.78%—Perl Module LoadAI7/7/20267/7/2026
Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to specify arbitrary module paths. Attackers able to influence module names passed to load could use that bug to execute arbitrary code.
AplazadaAlta (8.8)0.43%—AllcoachAI6/7/20266/7/2026
El plugin AllCoach para WordPress, en versiones anteriores a la 1.0.2, no comprueba si una dirección de correo electrónico enviada a un punto final público de registro de cuentas ya está asociada a un usuario existente antes de sobrescribir la contraseña de dicho usuario, lo que permite a atacantes no autenticados…
AplazadaBaja (2.1)0.37%—Sourcecodester Online Boat Reservation SystemAI5/7/20267/7/2026
A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AnalizadaMedia (4.8)0.28%—Redhat Build OF Keycloak5/7/202611/8/2026
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with trustEmail=true and the userinfo endpoint is enabled, Keycloak retrieves the email address from the userinfo response but retrieves the…
AplazadaAlta (8.1)0.25%—Dancer2 Plugin Auth Oauth ProviderAI4/7/20266/7/2026
Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the…
AplazadaAlta (8.1)0.23%—Plack Middleware OauthAI4/7/20266/7/2026
Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without…
AnalizadaBaja (2.7)0.38%—Redhat Build OF Keycloak3/7/202611/8/2026
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to…
AnalizadaMedia (5.4)0.32%—Redhat Build OF Keycloak3/7/202611/8/2026
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see…
ModificadaMedia (4.9)0.38%—Redhat Build OF Keycloak3/7/202631/8/2026
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of…
AplazadaMedia (5.3)0.35%—Ninjaforms Ninja Forms File UploadsAI3/7/20266/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log…
AplazadaCrítica (9.3)1.5%—Yonyou KsoaAI2/7/20262/7/2026
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters without any authentication, file type,…
AplazadaAlta (8.7)0.90%—Landray OAAI2/7/20261/10/2026
Landray OA contiene una vulnerabilidad de inyección HQL no autenticada que permite a atacantes no autenticados consultar clases de entidad Hibernate arbitrarias inyectando sintaxis HQL maliciosa en el parámetro POST uid del endpoint wechatLoginHelper.do. Los atacantes pueden explotar la falta de saneamiento de entrada…
AplazadaMedia (6.5)0.22%—Surbma Yoast SEO Breadcrumb ShortcodeAI2/7/20262/7/2026
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
AplazadaMedia (5.1)0.18%—Liboauth2AI2/7/20262/7/2026
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the…
AplazadaMedia (5.1)0.17%—Liboauth2AI2/7/20262/7/2026
liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is…