Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.38%—GhostAI1/10/20265/10/2026
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
AplazadaMedia (6.9)0.24%—GhostAI1/10/20261/10/2026
Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).
AplazadaAlta (8.7)0.32%—GhostAI1/10/20261/10/2026
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original…
AplazadaMedia (5.3)0.26%—GhostAI1/10/20261/10/2026
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended…
AplazadaAlta (7.1)0.30%—GhostAI1/10/20265/10/2026
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the…
AplazadaMedia (5.3)0.22%—WP Hosting AS PAY With Vipps FOR WoocommerceAI30/9/202630/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.
Pendiente de análisisBaja (2.1)0.44%—Artifex GhostscriptAI30/9/202630/9/2026
A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might…
AplazadaAlta (7.5)0.29%—Hostinger MigratorAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
AplazadaMedia (6.8)0.24%—Hostinger ReachAI30/9/202630/9/2026
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content…
Pendiente de análisisAlta (7)0.16%—GhostscriptAI29/9/202630/9/2026
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any…
Pendiente de análisisAlta (8.8)1.5%—Solarwinds Observability Self-hostedAI22/9/202624/9/2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Pendiente de análisisCrítica (9.8)0.65%—Solarwinds Observability Self-hostedAI22/9/202624/9/2026
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
AplazadaMedia (4.4)0.19%—Kibokolabs HostelAI22/9/202622/9/2026
The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
Pendiente de análisisMedia (5.3)0.17%—Espressif Esp-hostedAI21/9/202622/9/2026
The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to pb_istream_from_buffer(frame.data_value, frame.data_length) without…
AplazadaMedia (4.7)0.40%—WP GhostAI19/9/202621/9/2026
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if…
AplazadaAlta (8.8)0.66%—GhostscriptAIGnupgAISyslifters SysreptorAI18/9/202622/9/2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that…
AplazadaMedia (5.3)0.34%—Wpplugins Hide MY WP GhostAI18/9/202618/9/2026
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing…
AplazadaMedia (5.3)0.34%—Wpplugins Hide MY WP GhostAI18/9/202618/9/2026
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated…
Pendiente de análisisCrítica (9.3)0.78%—GhostscriptAI15/9/202624/9/2026
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare…
AplazadaBaja (2.1)0.37%—Phpgurukul Hostel Management SystemAI15/9/202615/9/2026
A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AplazadaBaja (1.9)0.37%—Phpgurukul Hostel Management SystemAI15/9/202615/9/2026
A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaAlta (8.8)2.9%—Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+19/9/20269/9/2026
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —…
AplazadaAlta (7)0.18%—Opentelemetry Resources HostAI8/9/202610/9/2026
`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by…
AplazadaAlta (7.2)0.27%—Wpplugins Hide MY WP GhostAI8/9/20268/9/2026
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
AplazadaAlta (8.8)0.43%—Ankara Hosting Site Management PanelAI31/8/20261/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.