Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Jthemes Themebox - Digital Products EcommerceAI | 27/5/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox - Digital Products Ecommerce allows Reflected XSS. This issue affects Themebox - Digital Products Ecommerce: from n/a through 1.4.2. | |
| Aplazada | Alta (7.1) | 0.22% | — | Digital Operations Services INC WifiburadaAI | 21/5/2026 | 23/7/2026 | Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Alta (8.2) | 0.52% | — | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied event parameter strings to atoms using String.to_atom/1 without validation:… | |
| Aplazada | Crítica (9.5) | 2.1% | 💥 PoC | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_event/3 accepts arbitrary… | |
| Aplazada | Baja (2.3) | 0.53% | — | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.ex reads a PubSub topic… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Ids6 Dsspro Digital Signage SystemAI | 16/5/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts. | |
| Aplazada | Alta (8.7) | 0.50% | — | Supsystic Digital PublicationsAI | 16/5/2026 | 29/9/2026 | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site… | |
| Aplazada | Alta (7.1) | 0.60% | — | Videoflow Digital Video Protection DVPAI | 29/4/2026 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers with valid credentials to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, download.pl,… | |
| Aplazada | Media (5.3) | 0.21% | — | Videoflow Digital Video Protection DVPAI | 29/4/2026 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can leverage the CSRF… | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | 💥 PoC | Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI | 16/4/2026 | 17/6/2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Crítica (9.8) | 0.61% | — | Delmaredigital Payload-puck | 7/4/2026 | 24/7/2026 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option… | |
| Modificada | Crítica (9.1) | 0.50% | — | Digitalbazaar Forge | 27/3/2026 | 4/9/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows… | |
| Modificada | Alta (7.5) | 0.47% | — | Digitalbazaar Forge | 27/3/2026 | 4/9/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both… | |
| Modificada | Alta (7.5) | 0.45% | — | Digitalbazaar Forge | 27/3/2026 | 10/9/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in… | |
| Modificada | Alta (7.5) | 0.90% | — | Digitalbazaar Forge | 27/3/2026 | 4/9/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When… | |
| Aplazada | Media (6.5) | 0.22% | — | Stratospheredigital WP Courses LMSAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Courses LMS wp-courses allows DOM-Based XSS.This issue affects WP Courses LMS: from n/a through <= 3.2.26. | |
| Pendiente de análisis | Alta (8.8) | 2.5% | 💥 PoC | Digitalocean Droplet AgentAI | 23/3/2026 | 17/6/2026 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without… | |
| Pendiente de análisis | Alta (8.6) | 0.51% | — | Slovensko.digital AutogramAI | 19/3/2026 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful… | |
| Aplazada | Media (5.3) | 0.29% | — | Raratheme Digital DownloadAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Digital Download digital-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Digital Download: from n/a through <= 1.1.4. | |
| Aplazada | Alta (8.8) | 0.31% | — | XoodigitalAI | 12/3/2026 | 17/6/2026 | XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database information. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mwtemplates DeepdigitalAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mwtemplates DeepDigital deepdigital allows Reflected XSS.This issue affects DeepDigital: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.4) | 0.14% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege. | |
| Aplazada | Alta (8.5) | 0.11% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Media (4.8) | 0.16% | — | Hcltech Digital Experience | 20/2/2026 | 17/6/2026 | HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit. |