Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
9645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thrive Quiz BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Whitestudio Easy Form BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Enquiry FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Funnelkit Funnel Builder PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Funnelkit Funnel Builder PROAI | 23/7/2026 | 23/7/2026 | Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | |
| Aplazada | Media (6.7) | 0.38% | — | QuickcalAI | 23/7/2026 | 23/7/2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | |
| Aplazada | Baja (1.9) | 1.1% | — | Syncfusion Ej2-javascript-ui-controlsAI | 22/7/2026 | 23/7/2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (6.5) | 0.35% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory. | |
| Analizada | Media (5.3) | 0.43% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion. | |
| Analizada | Media (6.5) | 0.42% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication… | |
| Analizada | Alta (8.1) | 0.50% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. | |
| Analizada | Alta (7.5) | 0.36% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests. | |
| Analizada | Media (5.9) | 0.16% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation. | |
| Analizada | Alta (8.1) | 0.34% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation. | |
| Analizada | Alta (8.1) | 0.73% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. | |
| Analizada | Alta (8.1) | 0.67% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. | |
| Analizada | Alta (7.5) | 0.27% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit… | |
| Analizada | Alta (7.5) | 0.45% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values. | |
| Analizada | Alta (7.5) | 0.50% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers. | |
| Analizada | Alta (8.1) | 0.74% | 💥 PoC | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. | |
| Aplazada | Crítica (9.4) | 0.38% | — | Joomla Page Builder CKAI | 22/7/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | |
| Analizada | Media (6.3) | 0.26% | — | Oracle E-business Suite | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Succession planning. Successful… | |
| Analizada | Alta (7.6) | 0.32% | — | Oracle E-business Suite | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling.… | |
| Analizada | Media (5.3) | 0.16% | — | Oracle E-business Suite | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling.… |