Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.23% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Cusrev Customer Reviews FOR WoocommerceAI | 25/9/2026 | 25/9/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Gerrit Code ReviewAI | 24/9/2026 | 25/9/2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex filter endpoints (RegexListSearcher /projects/?r= and RefFilter /projects/{project}/branches/?r=) in Gerrit Code Review… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Gerrit Code ReviewAI | 24/9/2026 | 25/9/2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthenticated remote attacker (or an authenticated user if anonymous read access is… | |
| Pendiente de análisis | Alta (7.6) | 0.25% | — | Gerrit Code ReviewAI | 24/9/2026 | 25/9/2026 | Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an authenticated user (or an unauthenticated user if the… | |
| Aplazada | Alta (8.5) | 0.27% | — | Taskview CommunityAI | 24/9/2026 | 5/10/2026 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers… | |
| Aplazada | Alta (8.7) | 0.42% | — | PhotoviewAI | 23/9/2026 | 24/9/2026 | Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 23/9/2026 | 23/9/2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 23/9/2026 | 23/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried… | |
| Aplazada | Alta (7.1) | 0.23% | — | PhotoviewAI | 22/9/2026 | 24/9/2026 | Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 22/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 22/9/2026 | 25/9/2026 | A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Alta (7.2) | 0.43% | — | Ljapps WP Yelp Review SliderAI | 22/9/2026 | 22/9/2026 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.1) | 0.36% | — | Wpmet WP Ultimate ReviewAI | 22/9/2026 | 22/9/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 22/9/2026 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 24/9/2026 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Online Reviewer Management SystemAI | 20/9/2026 | 22/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (6.1) | 0.33% | — | Gowebsolutions WP Customer ReviewsAI | 19/9/2026 | 21/9/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.2) | 0.40% | — | File-viewer DOCAIMsdoc ViewerAI | 18/9/2026 | 24/9/2026 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without… | |
| Aplazada | Crítica (9.1) | 0.21% | — | Keking KkfileviewAI | 16/9/2026 | 22/9/2026 | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filter is not the same parameter the controller actually fetches: the filter validates… | |
| Aplazada | Media (6.1) | 0.25% | — | Keking KkfileviewAI | 16/9/2026 | 22/9/2026 | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts. | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Media (5.1) | 0.24% | — | Solarview CompactAI | 14/9/2026 | 16/9/2026 | SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. |