Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
8601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.41% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency. The dependency only checks that the… | |
| Aplazada | Alta (8.1) | 0.41% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on… | |
| Aplazada | Alta (8.8) | 0.51% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by privileged workspace-management routes… | |
| Aplazada | Alta (8.8) | 0.51% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by… | |
| Pendiente de análisis | Media (4.3) | 0.38% | — | Nvidia Transformers4recAI | 21/7/2026 | 21/7/2026 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Aplazada | Alta (8.7) | 0.58% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 22/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields.… | |
| Aplazada | Media (6.9) | 0.49% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a… | |
| Aplazada | Alta (7.1) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 23/7/2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding… | |
| Aplazada | Alta (8.4) | 0.44% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Ninjaforms Ninja FormsAI | 21/7/2026 | 21/7/2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the… | |
| Aplazada | Media (6.9) | 0.47% | — | Parseplatform Parse ServerAI | 21/7/2026 | 23/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL… | |
| Aplazada | Alta (7.5) | 0.45% | — | Bpost Shipping PlatformAI | 21/7/2026 | 21/7/2026 | The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3. | |
| Aplazada | Media (6.5) | 0.34% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to re-trigger a form's configured workflow actions such as notification emails and integrations. | |
| Aplazada | Media (5.9) | 0.40% | — | Bitapps BIT FormAI | 21/7/2026 | 21/7/2026 | The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file. | |
| Aplazada | Media (4.9) | 0.29% | — | WpformsAI | 21/7/2026 | 21/7/2026 | The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Whitestudio Easy Form BuilderAI | 21/7/2026 | 21/7/2026 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Kvcache-ai KtransformersAI | 20/7/2026 | 23/7/2026 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious… | |
| Aplazada | Alta (8.6) | 0.51% | — | HeyformAI | 20/7/2026 | 22/7/2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX, XLS/XLSX, CSV, TXT, MP4, images, etc.,… | |
| Aplazada | Media (5.8) | 0.34% | — | HeyformAI | 20/7/2026 | 22/7/2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim in `submission.hiddenFields`, without validating the supplied `id`/`name` against the form's declared `form.hiddenFields` schema. An… | |
| Aplazada | Media (6.4) | 0.57% | — | HeyformAI | 20/7/2026 | 22/7/2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored in the static assets directory and served with `Content-Type: image/svg+xml` by Express's serve-static middleware, allowing an attacker to… | |
| Aplazada | Crítica (9) | 0.49% | — | HeyformAI | 20/7/2026 | 21/8/2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege… | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. | |
| Analizada | Alta (8.7) | 3.6% | — | Systeminformation | 17/7/2026 | 29/7/2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path>… | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Engineering Consulting Laboratory Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 through… | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… |