Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.59% | — | Apache Storm | 13/4/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and… | |
| Analizada | Alta (8.8) | 1.1% | — | Apache Storm | 13/4/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An… | |
| Aplazada | Alta (7.6) | 0.38% | — | Brainstormforce OttokitAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from n/a through <= 1.1.20. | |
| Aplazada | Media (4.3) | 0.23% | — | Brainstormforce CartflowsAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 1/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4. | |
| Aplazada | Alta (7.5) | 1.2% | 💥 Exploit | Brainstormforce SureformsAI | 28/3/2026 | 17/6/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the create_payment_intent() function performing a payment validation solely based on the value of a user-controlled parameter.… | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Astra Bulk EditAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edit allows DOM-Based XSS.This issue affects Astra Bulk Edit: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.4) | 0.35% | — | Brainstormforce AstraAI | 11/3/2026 | 17/6/2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the… | |
| Aplazada | Media (6.5) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through <= 3.21.1. | |
| Aplazada | Alta (7.2) | 0.38% | — | Brainstormforce CartflowsAI | 19/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19. | |
| Aplazada | Media (5.3) | 0.26% | — | Brainstormforce SpectraAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17. | |
| Aplazada | Media (4.3) | 0.13% | — | Brainstormforce SigmizeAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through <= 0.0.9. | |
| Aplazada | Alta (8.5) | 0.18% | — | Stormcloud SharemouseAI | 28/1/2026 | 17/6/2026 | ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the insecure service path configuration by placing malicious executables in specific system directories to gain elevated access during… | |
| Aplazada | Alta (7.6) | 0.32% | — | Firestormplugins Firestorm Professional Real EstateAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through <= 2.7.11. | |
| Aplazada | Media (5.9) | 0.31% | — | Brainstormforce Astra WidgetsAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.16. | |
| Aplazada | Alta (7.2) | 0.37% | 💥 PoC | Brainstormforce SureformsAI | 21/12/2025 | 28/9/2026 | The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (5.4) | 0.25% | — | Brainstormforce SpectraAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0. | |
| Aplazada | Media (5.3) | 0.20% | — | Brainstormforce SureformsAI | 19/11/2025 | 17/6/2026 | The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugin legitimately needs… | |
| Aplazada | Media (5.3) | 0.79% | 💥 Exploit | Brainstormforce SureformsAI | 13/11/2025 | 17/6/2026 | The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter to '__return_true', which allows unauthenticated access to the metadata. This… | |
| Aplazada | Alta (7.1) | 0.24% | — | Brainstormforce SurerankAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force SureRank surerank.This issue affects SureRank: from n/a through <= 1.3.2. | |
| Aplazada | Media (6.5) | 0.17% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Stored XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through < 3.21.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Brainstormforce SureformsAI | 14/10/2025 | 17/6/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.12.1. This is due to improper access control implementation on the '/wp-json/sureforms/v1/srfm-global-settings' REST API endpoint. This makes it… | |
| Aplazada | Media (4.3) | 0.18% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/10/2025 | 17/6/2026 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability. | |
| Analizada | Alta (7.5) | 0.34% | — | Stormshield Network Security | 25/9/2025 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing. | |
| Aplazada | Baja (3.5) | 0.19% | — | Brainstormforce SureformsAI | 23/9/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks. |