Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

21.068 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.43%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI8/9/20269/9/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high…
AplazadaCrítica (9.4)0.58%—Bahelievler Municipality Bihayat APPAI7/9/202630/9/2026
Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 before 2.3.
AplazadaBaja (2.1)0.39%—Bookstackapp BookstackAI7/9/20269/9/2026
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack…
AplazadaCrítica (9.8)0.91%💥 PoCDynamiapps Frontend AdminAI6/9/20268/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its…
AplazadaMedia (6.4)0.20%—Social Chat Click TO Chat APP ButtonAI5/9/20268/9/2026
The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (8.2)0.60%—Frappe CRMAI4/9/20269/9/2026
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0.
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
AnalizadaMedia (6.5)0.29%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
AnalizadaMedia (5.5)0.09%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/202610/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
AnalizadaMedia (5.5)0.10%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20268/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
AnalizadaMedia (5.7)0.22%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities.
AnalizadaAlta (7.5)0.55%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
AnalizadaMedia (5.5)0.11%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20269/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
AplazadaMedia (6)0.40%—Appflowy CloudAI4/9/202610/9/2026
AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages with victim object identifiers to read…
AplazadaAlta (7.7)0.57%—Appflowy-cloudAI4/9/202610/9/2026
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete…
AnalizadaAlta (7.7)0.38%—IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os4/9/20268/9/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
AplazadaMedia (6.9)0.55%—Slinkapp SlinkAI4/9/202623/9/2026
Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and…
AnalizadaAlta (8.7)0.48%—Snipeitapp Snipe-it4/9/202616/9/2026
snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable…
AnalizadaAlta (8.4)0.38%—Snipeitapp Snipe-it4/9/202616/9/2026
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging…
AplazadaAlta (8.8)0.43%—Canva Android APPAI4/9/20268/9/2026
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
AplazadaCrítica (9.6)0.39%—Canva Android APPAI4/9/20268/9/2026
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
AplazadaMedia (5.9)0.38%—Dynamiapps Frontend AdminAI4/9/20268/9/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the…
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/20264/9/2026
A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/202611/9/2026
A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.