Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.46% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to make limited unauthorized modifications to the underlying operating system and disrupt the availability of the… | |
| Modificada | Alta (8.3) | 0.33% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary… | |
| Modificada | Alta (8.3) | 0.41% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system. | |
| Modificada | Alta (8.5) | 0.34% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform, including changes to the… | |
| Modificada | Alta (8.6) | 0.46% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to obtain limited system information and to change the state of certain settings of a vulnerable system. Successful exploitation could allow an attacker to gain insight into internal services and workflows and… | |
| Modificada | Alta (8.8) | 0.62% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete… | |
| Modificada | Alta (8.8) | 0.53% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete compromise of the affected system. | |
| Modificada | Alta (8.8) | 0.34% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's… | |
| Modificada | Alta (8.8) | 0.42% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. | |
| Analizada | Crítica (9) | 0.67% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to… | |
| Analizada | Crítica (9) | 0.42% | — | Arubanetworks Fabric Composer | 1/9/2026 | 2/9/2026 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary… | |
| Analizada | Crítica (9.6) | 0.26% | — | Arubanetworks Fabric Composer | 1/9/2026 | 4/9/2026 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host. | |
| Aplazada | Media (6.4) | 0.20% | — | Live ComposerAI | 1/9/2026 | 1/9/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.20% | — | Live ComposerAI | 1/9/2026 | 1/9/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.19% | — | Live ComposerAI | 1/9/2026 | 2/9/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Live ComposerAI | 1/9/2026 | 1/9/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due to insufficient input sanitization and output… | |
| Aplazada | Media (6.4) | 0.17% | — | Tagdiv ComposerAI | 25/8/2026 | 28/9/2026 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which base64-decodes shortcode content (after a… | |
| Aplazada | Media (5.4) | 0.29% | — | HCL Digital ExperienceAIHCL Digital Experience ComposeAI | 5/8/2026 | 28/8/2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | |
| Aplazada | Media (4.3) | 0.25% | — | Cleverplugins Clever Mega Menu FOR Visual ComposerAI | 2/8/2026 | 26/8/2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public… | |
| Aplazada | Media (5) | 0.28% | — | Visualcomposer Visual ComposerAI | 27/7/2026 | 27/7/2026 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | |
| Pendiente de análisis | Alta (7.5) | 1.0% | — | ComposerAI | 15/7/2026 | 15/7/2026 | Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Tagdiv ComposerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3. | |
| Pendiente de análisis | Media (5.9) | 0.35% | — | Drupal ComposerAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. | |
| Aplazada | Alta (7) | 0.16% | — | ComposerAI | 8/7/2026 | 10/7/2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update… | |
| Aplazada | Media (4.7) | 0.14% | — | ComposerAI | 8/7/2026 | 10/7/2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper,… |