Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
8599 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.64% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vimesoft INC Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Media (6.5) | 0.36% | — | GIS Informatics Engineering Consulting Laboratory RND AND Software Services Gislab Laboratory Management SystemAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management System: from 1.4.03 through 08072026. | |
| Aplazada | Alta (8.7) | 0.44% | — | Joomla ChronoformsAIJoomlaAI | 17/7/2026 | 23/7/2026 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Firebase StudioAIGoogle Cloud PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is… | |
| Aplazada | Media (6.1) | 0.27% | — | NEX FormsAI | 17/7/2026 | 17/7/2026 | The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high… | |
| Aplazada | Media (6.4) | 0.26% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or… | |
| Aplazada | Alta (7.2) | 0.43% | — | Kaliforms Kali FormsAI | 17/7/2026 | 17/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.66% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary… | |
| Aplazada | Media (4.3) | 0.28% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Aplazada | Alta (8.7) | 0.54% | — | Axelor Open PlatformAI | 16/7/2026 | 17/7/2026 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by… | |
| Aplazada | Alta (7.5) | 0.93% | — | Gravityforms Gravity FormsAI | 15/7/2026 | 15/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Analizada | Media (6.5) | 0.32% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the… | |
| Analizada | Alta (7.2) | 0.57% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a user who holds a role that contains the `edit_local_apps` and `install_apps` capabilities could cause a legitimate app installation to… | |
| Analizada | Alta (8.3) | 0.18% | — | SplunkSplunk Cloud Platform | 15/7/2026 | 24/7/2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing… | |
| Analizada | Media (4.8) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (4.6) | 0.24% | — | Pega Platform | 15/7/2026 | 21/7/2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Aplazada | Alta (7.2) | 0.46% | — | Getgrav GravAINeos FormAI | 15/7/2026 | 15/7/2026 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through… | |
| Aplazada | Alta (7.1) | 0.38% | — | Praisonai PlatformAI | 15/7/2026 | 18/7/2026 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label… | |
| Aplazada | Media (5.5) | 0.32% | — | Kaliforms Kali FormsAI | 15/7/2026 | 15/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own… | |
| Aplazada | Media (5.3) | 0.39% | — | Kali Forms Contact Form AND Drag AND Drop BuilderAI | 15/7/2026 | 15/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | HCL Bigfix PlatformAI | 14/7/2026 | 15/7/2026 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service. | |
| Analizada | Alta (8.7) | 0.50% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 16/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the… | |
| Analizada | Crítica (9.2) | 4.4% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint.… |