Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
8600 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.58% | — | Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026. | |
| Aplazada | Alta (7.1) | 0.41% | — | Praisonai PlatformAI | 10/7/2026 | 10/7/2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an… | |
| Aplazada | Media (4.3) | 0.37% | 💥 PoC | FlowformsAI | 10/7/2026 | 14/7/2026 | The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.6) | 0.87% | — | HappyformsAI | 10/7/2026 | 29/9/2026 | El plugin Happyforms - Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms para WordPress es vulnerable a inclusión local de ficheros en todas las versiones hasta la 1.26.12, inclusive, a través de la función happyforms_get_form_partial(). Esto hace posible que atacantes… | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.47% | — | Sureforms Drag AND Drop Form BuilderAI | 10/7/2026 | 14/7/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and… | |
| Aplazada | Media (5.4) | 0.30% | — | Fluentcrm Fluent FormsAI | 10/7/2026 | 10/7/2026 | The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 5.1% | 💥 Exploit | Super-forms Super FormsAI | 10/7/2026 | 10/7/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only… | |
| Aplazada | Alta (7.5) | 0.62% | — | Docuform Gmbh FSM ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames… | |
| Aplazada | Alta (8.1) | 0.55% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files. | |
| Aplazada | Alta (8.1) | 0.57% | — | Docuform Gmbh ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component | |
| Aplazada | Alta (8.1) | 0.68% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts. | |
| Aplazada | Media (5.4) | 0.23% | — | Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398. | |
| Aplazada | Alta (7.2) | 0.32% | — | WP Cost Estimation Payment Forms BuilderAI | 9/7/2026 | 9/7/2026 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa💥 Exploit | Balbooa Forms | 9/7/2026 | 24/7/2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Aplazada | Alta (7.1) | 1.1% | — | Bitapps BIT FormAI | 9/7/2026 | 9/7/2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.59% | — | Connect Contact Form 7 AND MailchimpAI | 9/7/2026 | 9/7/2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.30% | — | Wpeverest Everest FormsAI | 9/7/2026 | 9/7/2026 | The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpeverest Everest FormsAI | 9/7/2026 | 9/7/2026 | The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable… | |
| Aplazada | Alta (8.8) | 0.44% | — | Elegantthemes Divi Form BuilderAI | 9/7/2026 | 9/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and… | |
| Aplazada | Baja (2.3) | 0.53% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,… | |
| Aplazada | Alta (8.7) | 0.59% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal… | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Snowflake Terraform ProviderAI | 8/7/2026 | 9/7/2026 | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of… | |
| Aplazada | Media (6.5) | 0.38% | — | Nomysoft Informatics Education AND Consulting INC NomysemAI | 8/7/2026 | 8/7/2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did… | |
| Aplazada | Crítica (9.1) | 1.2% | — | Simple Coherent FormAI | 8/7/2026 | 8/7/2026 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily… |