Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6555 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.31% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON… | |
| Aplazada | Alta (7.1) | 0.20% | — | Nezha DashboardAI | 3/10/2026 | 5/10/2026 | Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests. | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | 💥 PoC | Image-downloaderAI | 2/10/2026 | 3/10/2026 | Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory. | |
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Simple Loan Management SystemAI | 2/10/2026 | 6/10/2026 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (6.4) | 0.22% | — | Download ManagerAI | 2/10/2026 | 3/10/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Alta (7.2) | 0.24% | — | Mangboard Mang BoardAI | 2/10/2026 | 3/10/2026 | The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.2) | 0.31% | — | Download MonitorAI | 2/10/2026 | 2/10/2026 | The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | KeycloakAI | 1/10/2026 | 1/10/2026 | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Oauth-proxyAI | 1/10/2026 | 6/10/2026 | A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external… | |
| Aplazada | Media (6.4) | 0.20% | — | Download ManagerAI | 1/10/2026 | 1/10/2026 | The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 5/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these… | |
| Aplazada | Media (6.5) | 0.13% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | |
| Aplazada | Crítica (9.8) | 0.30% | — | Oauth Single Sign ON SSOAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Aplazada | Media (6.3) | 0.25% | — | FluentboardsAI | 30/9/2026 | 30/9/2026 | Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | Viable URL Media UploaderAI | 30/9/2026 | 30/9/2026 | The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (4.3) | 0.15% | — | ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | |
| Aplazada | Alta (8.8) | 0.28% | — | Wpeverest ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim… | |
| Analizada | Crítica (9.5) | 0.32% | 💥 PoC | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component… | |
| Analizada | Alta (8.9) | 0.37% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the… |