Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
9646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.38% | — | RebuildAI | 29/9/2026 | 29/9/2026 | A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Alta (7.4) | 0.47% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated… | |
| Aplazada | Baja (2.1) | 1.6% | — | Raspap WebguiAI | 29/9/2026 | 1/10/2026 | A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched… | |
| Aplazada | Baja (2) | 2.1% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The… | |
| Aplazada | Media (5.3) | 0.35% | — | Ag-ui-protocol Ag-uiAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of… | |
| Aplazada | Media (5.3) | 0.30% | — | Ag-ui-protocol Ag-uiAI | 28/9/2026 | 28/9/2026 | A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be… | |
| Aplazada | Media (5.3) | 0.51% | — | Ag-ui-protocol Ag-uiAI | 28/9/2026 | 1/10/2026 | A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits… | |
| Aplazada | Media (5.3) | 0.51% | — | Ag-ui-protocol Ag-uiAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this… | |
| Aplazada | Baja (2) | 0.20% | — | XunruicmsAI | 28/9/2026 | 1/10/2026 | A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (6.8) | 0.22% | — | SPS SuiteAI | 28/9/2026 | 28/9/2026 | The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Media (5.1) | 0.16% | — | Fuzui StudentinfoAI | 28/9/2026 | 1/10/2026 | A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to… | |
| Aplazada | Alta (7.5) | 0.36% | — | Ciena Navigator Network Control SuiteAI | 25/9/2026 | 28/9/2026 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information. | |
| Aplazada | Media (6.2) | 0.11% | — | EspruinoAI | 25/9/2026 | 30/9/2026 | Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, the missing assertion guard allows a write through the NULL pointer,… | |
| Aplazada | Alta (7.2) | 0.26% | — | User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.27% | — | Themify BuilderAI | 25/9/2026 | 25/9/2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.4) | 0.20% | — | Codeselling User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.32% | — | EspruinoAI | 24/9/2026 | 25/9/2026 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintTokenLineMarker(), which passes the address of a 4-byte int column… | |
| Aplazada | Alta (7.7) | 0.17% | — | EspruinoAI | 24/9/2026 | 24/9/2026 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer,… | |
| Pendiente de análisis | Crítica (9.8) | 0.45% | — | QuickjsAI | 24/9/2026 | 29/9/2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | |
| Aplazada | Media (6.5) | 0.25% | — | Lasuite DOCAI | 24/9/2026 | 5/10/2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document paths to scope descendant searches without requiring the caller to possess the public document UUID. An unauthenticated caller can submit an empty… | |
| Pendiente de análisis | Crítica (9.2) | 0.33% | — | Portswigger Burp Suite DastAI | 24/9/2026 | 24/9/2026 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. | |
| Pendiente de análisis | Alta (8.6) | 0.43% | — | IBM Enterprise Build OF QuarkusAI | 24/9/2026 | 24/9/2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Aplazada | Crítica (9.8) | 2.9% | — | Visualcomposer Visual Composer Website BuilderAI | 24/9/2026 | 24/9/2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Media (6.5) | 0.11% | — | Fabasoft Folio ClientAIFabasoft Egov-suiteAI | 24/9/2026 | 26/9/2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,… |