Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
21.067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.58% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire database. This issue has been patched in… | |
| Aplazada | Alta (7.5) | 0.22% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. An attacker can trick a victim into… | |
| Aplazada | Alta (7.5) | 0.46% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has… | |
| Aplazada | Media (4.3) | 0.26% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal authenticated user without their own provider key… | |
| Aplazada | Media (4.3) | 0.29% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another user. The write is accepted, and later the stats logic dereferences that foreign… | |
| Aplazada | Alta (7.1) | 0.41% | — | Frappe FrameworkAI | 30/8/2026 | 10/9/2026 | Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary SELECT statements against unrelated… | |
| Aplazada | Alta (8.7) | 1.00% | — | Bookstackapp BookstackAI | 29/8/2026 | 8/10/2026 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename… | |
| Aplazada | Media (4.3) | 0.25% | — | Dynamiapps Frontend AdminAI | 29/8/2026 | 31/8/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 29/8/2026 | 31/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were… | |
| Aplazada | Alta (7.5) | 0.36% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 29/8/2026 | 31/8/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price. | |
| Pendiente de análisis | Baja (2.3) | 0.25% | — | Netapp StoragegridAI | 28/8/2026 | 1/9/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service. | |
| Pendiente de análisis | Crítica (9.9) | 0.29% | — | IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI | 28/8/2026 | 31/8/2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining… | |
| Pendiente de análisis | Media (4.3) | 0.38% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM… | |
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of… | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | 💥 PoC | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is… | |
| Pendiente de análisis | Alta (7.5) | 1.7% | 💥 Exploit | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configured staticRoots. A path containing traversal segments can escape the… | |
| Pendiente de análisis | Media (6.5) | 1.3% | 💥 Exploit | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java and… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java. Any authenticated account can call GET /api/roles, GET /api/roles/{name}, and… | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket, ProcessingApi.subscribeAlgorithmStatus… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event… | |
| Pendiente de análisis | Crítica (9.1) | 0.68% | 💥 PoC | Spaceapplications YamcsAI | 28/8/2026 | 8/9/2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate reaches… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Plone.app.portletsAI | 28/8/2026 | 9/9/2026 | plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Plone APP EventAI | 28/8/2026 | 9/9/2026 | plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in… | |
| Aplazada | Media (4.8) | 0.24% | — | Bitapps BIT AssistAI | 28/8/2026 | 1/9/2026 | WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account. | |
| Analizada | Media (5.1) | 0.30% | — | Frappe | 27/8/2026 | 31/8/2026 | Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in frappe/desk/doctype/workspace_link/workspace_link.json, and _sanitize_content() in frappe/model/base_document.py skips… |