Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

6569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.60%—Ninjaforms Ninja Forms File UploadsAI2/7/20262/7/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a…
AplazadaMedia (6.5)0.44%—Goadmingroup GoadminAI1/7/20262/7/2026
SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints
AplazadaMedia (5.3)0.29%—WP Reloaded ApplyonlineAI1/7/20261/7/2026
Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.
AplazadaMedia (6.4)0.36%—Download ManagerAI1/7/20261/7/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaMedia (6.5)0.49%—Redhat Build OF Keycloak30/6/20265/8/2026
A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege…
ModificadaMedia (4.3)0.39%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack30/6/20265/8/2026
A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific…
AnalizadaMedia (6.5)0.40%—Redhat Build OF Keycloak30/6/20261/7/2026
A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns…
AplazadaAlta (7.2)0.32%—Connekthq Ajax Load More FiltersAI30/6/202630/6/2026
The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AnalizadaAlta (7.9)0.68%—Amazon Application Load Balancer29/6/20261/7/2026
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2…
AplazadaAlta (7.7)0.46%—ModoboaAI29/6/20261/7/2026
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve…
AplazadaAlta (8.7)0.64%—PhpuploaderAI29/6/202614/7/2026
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result…
AplazadaMedia (5.3)0.36%—PayloadcmsAI26/6/202626/6/2026
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
AnalizadaAlta (8.1)0.30%—Redhat Build OF Keycloak25/6/202615/7/2026
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any…
AplazadaAlta (7)0.31%—CanboatAI25/6/202614/7/2026
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-over-IP to trigger an…
AplazadaMedia (5.3)0.48%—KanboardAI25/6/202614/7/2026
Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessions. Attackers can enumerate sequential session IDs and…
ModificadaAlta (8.1)0.65%—Redhat Build OF Keycloak25/6/202614/9/2026
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query…
AnalizadaMedia (4.6)0.29%—Redhat Build OF Keycloak25/6/20261/7/2026
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of…
AnalizadaMedia (6.5)0.46%—Redhat Build OF Keycloak25/6/20261/7/2026
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the…
AnalizadaAlta (7.7)0.49%—Redhat Build OF Keycloak25/6/202615/7/2026
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management…
AnalizadaAlta (7.3)0.78%💥 PoCRedhat Build OF Keycloak25/6/202615/7/2026
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted…
AnalizadaMedia (4.9)0.78%—Redhat Build OF Keycloak25/6/20261/7/2026
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore parameter when creating a key provider component. This allows the administrator to probe arbitrary filesystem paths, determining which files exist and…
AplazadaMedia (5.3)0.40%—Secufor OauthAI24/6/202625/6/2026
The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to disconnect the WordPress site from its linked…
AplazadaAlta (7.2)0.36%—Email Javascript CloakAI24/6/202625/6/2026
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.76%—Broadcom Spring Statemachine23/6/202622/9/2026
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring…
AplazadaMedia (6.5)0.60%—CboardAI23/6/20265/7/2026
SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component