Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.8) | 0.32% | — | Openfga Helm ChartsOpenfga | 18/8/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls… | |
| Aplazada | Crítica (10) | 2.1% | 💥 Exploit | Php-chartsAI | 5/8/2025 | 16/6/2026 | PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that injects arbitrary PHP code, resulting in command execution under the web server's… | |
| Modificada | Alta (7.8) | 0.18% | — | Autodesk Infrastructure Parts EditorAutodesk InventorAutodesk Navisworks ManageAutodesk Navisworks Simulate+2 | 24/7/2025 | 17/6/2026 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized. | |
| Aplazada | Crítica (10) | 0.70% | — | Bitnami Helm ChartsAI | 24/7/2025 | 17/6/2026 | Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing… | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Crafts AND ArtsAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5. | |
| Analizada | Media (5.8) | 0.48% | — | Openfga Helm ChartsOpenfga | 22/5/2025 | 17/6/2026 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific… | |
| Aplazada | Media (6.3) | 0.25% | — | SAP Service Parts ManagementAI | 13/5/2025 | 17/6/2026 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application. | |
| Aplazada | Media (6.3) | 0.25% | — | SAP Service Parts ManagementAI | 13/5/2025 | 17/6/2026 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on confidentiality, integrity and availability of the application. | |
| Analizada | Media (5.8) | 0.39% | — | Openfga Helm ChartsOpenfga | 30/4/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been… | |
| Modificada | Alta (7.8) | 0.29% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+13 | 15/4/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (8.5) | 0.45% | — | Randyjensen RJ QuickchartsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows SQL Injection.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Randyjensen Rj-quickchartsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows Stored XSS.This issue affects RJ Quickcharts: from n/a through <= 0.6.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Kiran Potphode Easy ChartsAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts easy-charts allows DOM-Based XSS.This issue affects Easy Charts: from n/a through <= 1.2.3. | |
| Analizada | Media (5.8) | 0.43% | — | Openfga Helm ChartsOpenfga | 19/2/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or… | |
| Analizada | Media (5.4) | 0.25% | — | Supporthost Simple Charts | 18/2/2025 | 17/6/2026 | The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.3) | 0.17% | — | Electronic Arts Dragon AGE OriginsAI | 27/1/2025 | 17/6/2026 | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to… | |
| Aplazada | Media (4.3) | 0.24% | — | Dotstore Product Size Charts Plugin FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5. | |
| Analizada | Media (5.4) | 0.22% | — | Nfusionsolutions Precious Metals Charts AND Widgets | 24/1/2025 | 17/6/2026 | The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Media (5.8) | 0.45% | — | Openfga Helm ChartsOpenfga | 13/1/2025 | 17/6/2026 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses… | |
| Aplazada | Alta (7.6) | 0.47% | — | Penguinarts Contact Form 7 Database Cfdb7AI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 advanced-cf7-database allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Smartsupp Live ChatAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross Site Request Forgery.This issue affects Smartsupp – live chat, chatbots, AI and lead generation: from n/a through <= 3.6. | |
| Aplazada | Alta (7.5) | 0.59% | — | Smarts-srl Smart AgentAI | 27/12/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted script to the /FB/getFbVideoSource.php component. | |
| Analizada | Crítica (9.8) | 0.89% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component. | |
| Analizada | Crítica (9.8) | 0.89% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component. | |
| Analizada | Alta (7.5) | 1.4% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the /youtubeInfo.php component. |