Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.9)3.3%—Rvc-boss Gpt-sovits-webui15/7/202517/6/2026
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. path_list takes user input, which is passed to the change_label function, which concatenates the user input into a command and runs it on the…
AnalizadaAlta (8.9)3.4%—Rvc-boss Gpt-sovits-webui15/7/202517/6/2026
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_asr function. asr_inp_dir (and a number of other variables) takes user input, which is passed to the open_asr function, which concatenates the user input into a…
AnalizadaAlta (8.9)3.3%—Rvc-boss Gpt-sovits-webui15/7/202517/6/2026
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_denoise function. denoise_inp_dir and denoise_opt_dir take user input, which is passed to the open_denoise function, which concatenates the user input into a…
AnalizadaAlta (8.9)3.4%—Rvc-boss Gpt-sovits-webui15/7/202517/6/2026
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the webui.py open_slice function. slice_opt_root and slice-inp-path takes user input, which is passed to the open_slice function, which concatenates the user input into a…
AplazadaCrítica (10)1.6%💥 ExploitDiskboss EnterpriseAI15/7/202517/6/2026
A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28, 7.5.12, and 8.2.14. The vulnerability arises from improper bounds checking on the path component of HTTP GET requests. By sending a specially crafted long URI, a remote unauthenticated attacker can…
ModificadaMedia (5.5)0.17%—Redhat Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackInfinispan26/6/202517/6/2026
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
ModificadaBaja (2.5)0.32%—Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise LinuxXmlsoft Libxml216/6/20256/10/2026
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern…
AplazadaAlta (8.6)0.49%—Joomla NO Boss CalendarAI13/6/202517/6/2026
A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.
ModificadaAlta (7.5)1.4%—Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+1612/6/202518/9/2026
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
ModificadaBaja (3.5)0.33%—Buddyboss Platform15/5/202517/6/2026
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
AnalizadaCrítica (9.8)0.66%—Buddyboss Platform5/5/202517/6/2026
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to…
ModificadaMedia (5.4)0.28%—Buddyboss Platform2/5/202517/6/2026
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and…
ModificadaMedia (5.4)0.28%—Buddyboss Platform2/5/202517/6/2026
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level…
ModificadaMedia (5.4)0.30%—Buddyboss Platform2/5/202517/6/2026
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (6.2)1.0%—WildflyAIRedhat Jboss Enterprise Application PlatformAIJboss MarshallingAI7/4/202519/8/2026
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object,…
AplazadaMedia (4.3)0.30%—CartbossAI1/4/202517/6/2026
Missing Authorization vulnerability in CartBoss CartBoss cartboss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartBoss: from n/a through <= 4.1.2.
ModificadaAlta (8.1)0.89%—Redhat Wildfly CoreRedhat Data GridRedhat Jboss Enterprise Application Platform4/3/202514/9/2026
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
AplazadaAlta (7.1)0.39%—Josh Harrison Yahoo BossAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Harrison Yahoo BOSS yahoo-boss allows Reflected XSS.This issue affects Yahoo BOSS: from n/a through <= 0.7.
AplazadaAlta (7.5)0.38%—Bosscomm If740AI28/2/202517/6/2026
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process.
AplazadaMedia (6.5)0.21%—Bosscomm If740AI28/2/202517/6/2026
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.
AplazadaMedia (6.2)0.16%—Bosscomm If740AI28/2/202517/6/2026
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.
AnalizadaMedia (5.4)0.24%—Buddyboss Platform27/2/202517/6/2026
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
ModificadaMedia (6.5)0.77%—Redhat Jboss Enterprise Application PlatformRedhat Wildfly30/1/202518/9/2026
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to…
AplazadaMedia (5.4)0.17%—Buddyboss LLC Buddyboss ThemeAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.
AplazadaMedia (5.3)0.53%—THE African Boss Checkout With Zelle ON WoocommerceAI13/12/202417/6/2026
Missing Authorization vulnerability in The African Boss Checkout with Zelle on Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout with Zelle on Woocommerce: from n/a through 3.1.
Orbitaley — Vulnerabilidades