Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

8600 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.58%—Semtek Informatics Software Consulting Trade LTD CO Sem-pmpAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026.
AplazadaAlta (7.1)0.41%—Praisonai PlatformAI10/7/202610/7/2026
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an…
AplazadaMedia (4.3)0.37%💥 PoCFlowformsAI10/7/202614/7/2026
The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via the update_form due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.6)0.87%—HappyformsAI10/7/202629/9/2026
El plugin Happyforms - Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms para WordPress es vulnerable a inclusión local de ficheros en todas las versiones hasta la 1.26.12, inclusive, a través de la función happyforms_get_form_partial(). Esto hace posible que atacantes…
AplazadaMedia (6.1)0.36%—Brevo Newsletter Smtp Email Marketing Subscribe FormsAI10/7/202610/7/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.5)0.47%—Sureforms Drag AND Drop Form BuilderAI10/7/202614/7/2026
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and…
AplazadaMedia (5.4)0.30%—Fluentcrm Fluent FormsAI10/7/202610/7/2026
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)5.1%💥 ExploitSuper-forms Super FormsAI10/7/202610/7/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only…
AplazadaAlta (7.5)0.62%—Docuform Gmbh FSM ClientAI9/7/202610/7/2026
An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames…
AplazadaAlta (8.1)0.55%—Docuform ClientAI9/7/202610/7/2026
A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.
AplazadaAlta (8.1)0.57%—Docuform Gmbh ClientAI9/7/202610/7/2026
An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component
AplazadaAlta (8.1)0.68%—Docuform ClientAI9/7/202610/7/2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.
AplazadaMedia (5.4)0.23%—Twiser Informatics Technology Consulting Trade AND Education INC Okrs & GoalsAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.
AplazadaAlta (7.2)0.32%—WP Cost Estimation Payment Forms BuilderAI9/7/20269/7/2026
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitBalbooa Forms9/7/202624/7/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AplazadaAlta (7.1)1.1%—Bitapps BIT FormAI9/7/20269/7/2026
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated…
AplazadaAlta (7.2)0.59%—Connect Contact Form 7 AND MailchimpAI9/7/20269/7/2026
The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.5)0.30%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header.…
AplazadaAlta (7.5)0.43%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable…
AplazadaAlta (8.8)0.44%—Elegantthemes Divi Form BuilderAI9/7/20269/7/2026
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and…
AplazadaBaja (2.3)0.53%—Parseplatform Parse ServerAI8/7/202610/7/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,…
AplazadaAlta (8.7)0.59%—Parseplatform Parse ServerAI8/7/202610/7/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal…
Pendiente de análisisAlta (8.8)0.53%—Snowflake Terraform ProviderAI8/7/20269/7/2026
Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of…
AplazadaMedia (6.5)0.38%—Nomysoft Informatics Education AND Consulting INC NomysemAI8/7/20268/7/2026
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did…
AplazadaCrítica (9.1)1.2%—Simple Coherent FormAI8/7/20268/7/2026
The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily…