Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

242 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.51%—Stylemixthemes Cost Calculator BuilderAI5/8/202612/8/2026
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a…
AplazadaCrítica (9.8)1.3%—Cost Calculator Builder PROAI29/7/202630/7/2026
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to…
AplazadaCrítica (9.3)0.41%—Calcom Cal.diyAI23/7/202630/7/2026
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, so an attacker who…
AplazadaCrítica (10)1.4%💥 PoCVercel Next.jsAICalcom Cal.diyAI23/7/202629/9/2026
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be…
Pendiente de análisisCrítica (9.6)0.40%—Calcom Cal.com OSSAI22/7/202627/7/2026
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering…
AnalizadaMedia (6.5)0.29%—Ncalc17/7/202618/8/2026
NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large factorial operands, causing excessive CPU consumption or a non-terminating loop due to integer overflow in…
AplazadaMedia (5.3)0.58%—Stylemixthemes Cost Calculator BuilderAI11/7/202613/7/2026
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded…
AplazadaMedia (4.6)0.19%—Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI7/7/20268/7/2026
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard…
AplazadaMedia (5.3)0.29%—EZ Form Calculator PremiumAI2/7/20262/7/2026
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
AplazadaAlta (7.5)0.39%—Stylish Cost CalculatorAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
AplazadaMedia (5.4)0.17%—Libreoffice CalcAI15/6/202617/6/2026
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed…
AplazadaMedia (5.4)0.23%—Libreoffice CalcAI15/6/202628/7/2026
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed…
AplazadaMedia (6.4)0.33%—Global Body Mass Index CalculatorAI9/6/202623/7/2026
The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes in the GBMI_Calc_Widget::widget()…
AnalizadaMedia (6.5)0.69%—Apache Calcite2/6/202622/7/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
AplazadaMedia (5.5)0.53%—Calcom Cal.diyAI24/5/202623/7/2026
A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes…
AplazadaBaja (1.3)0.32%—Calcom Cal.diyAI23/5/202623/7/2026
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature…
AplazadaBaja (2.1)0.23%—Calcom Cal.diyAI23/5/202623/7/2026
A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not…
AplazadaCrítica (9.8)0.86%—MCP Calculate ServerAISympyAI15/5/202617/6/2026
MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.
AplazadaMedia (6.4)0.33%—Algoritmika Cost OF Goods Product Cost Profit CalculatorAI13/5/202617/6/2026
The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output…
AplazadaMedia (5.3)0.23%—Stylemixthemes Cost Calculator BuilderAI13/5/20267/10/2026
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when used in combination with Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment AJAX action being…
AplazadaMedia (6.9)0.39%—Kanev CAB Fare CalculatorAI10/5/202624/7/2026
WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to include arbitrary files…
AplazadaMedia (5.3)0.26%—MWP Development Diet Calorie CalculatorAI8/4/202624/7/2026
Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.
AplazadaMedia (6.5)0.22%—Manoj Kumar MK Google-directionsAIManoj Kumar MK Google-distance-calculatorAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1.
AnalizadaCrítica (9.3)0.80%—Ticalc Tiemu28/3/202617/6/2026
TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadgets to bypass…
AplazadaAlta (8.6)0.16%—Ticalc TiemuAI28/3/202617/6/2026
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction…
Orbitaley — Vulnerabilidades