Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
8600 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 4.4% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint.… | |
| Analizada | Media (6.3) | 0.38% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 15/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the… | |
| Analizada | Alta (8.8) | 0.51% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such… | |
| Analizada | Alta (7) | 0.27% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 14/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation… | |
| Analizada | Media (5.3) | 0.31% | — | Dan-in-ca Sustainable Irrigation Platform | 14/7/2026 | 15/7/2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output… | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… | |
| Aplazada | Media (5.9) | 0.29% | — | Brainstormforce SureformsAI | 14/7/2026 | 14/7/2026 | The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected. | |
| Pendiente de análisis | Crítica (9.5) | 1.4% | 💥 Exploit | Servicenow AI PlatformAI | 13/7/2026 | 14/7/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to… | |
| Pendiente de análisis | Crítica (9.4) | 0.35% | — | Google Cloud BigqueryAIGoogle DataformAIGoogle Colab EnterpriseAI | 13/7/2026 | 13/7/2026 | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository… | |
| Aplazada | Alta (7.6) | 0.38% | — | Hannan Persian Gravity FormsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2. | |
| Aplazada | Alta (7.5) | 0.50% | — | Wpmudev ForminatorAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpmudev ForminatorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crmperks Contact Form EntriesAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Basixonline Nex-formsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Kofimokome Message Filter FOR Contact Form 7AI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crmperks CRM Perks FormsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wppool FormychatAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3. | |
| Aplazada | Alta (7.5) | 0.35% | — | Phil Kurth Advanced FormsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7. | |
| Aplazada | Media (5) | 0.22% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/7/2026 | 13/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry.… | |
| Aplazada | Baja (2.1) | 0.41% | — | Parseplatform Parse ServerAI | 11/7/2026 | 13/7/2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Content-Type that is not a valid type/subtype… | |
| Aplazada | Alta (7.1) | 0.46% | — | Praisonai PlatformAI | 11/7/2026 | 13/7/2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then… | |
| Aplazada | Media (5.3) | 0.47% | — | Basix NEX FormsAI | 11/7/2026 | 15/7/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite… | |
| Aplazada | Alta (7.2) | 0.40% | — | Wpvibes Form VibesAI | 11/7/2026 | 13/7/2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Pendiente de análisis | Media (5.9) | 0.33% | — | Drupal RAW FormatterAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. | |
| Analizada | Crítica (9.8) | 0.56% | — | Zroger Formatter Field | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. |