Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
40.059 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 2.9% | — | Netcore Nbr200v2AI | 20/9/2026 | 24/9/2026 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Crítica (9.3) | 0.98% | — | Dlink Dir-868lAI | 20/9/2026 | 22/9/2026 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a… | |
| Aplazada | Crítica (9.3) | 0.39% | 💥 PoC | Ordasoft Osgallery SearchAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a… | |
| Pendiente de análisis | Crítica (9.8) | 0.88% | 💥 PoC | RedcapAI | 20/9/2026 | 22/9/2026 | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted… | |
| Aplazada | Crítica (9.2) | 0.57% | — | NivocartAI | 20/9/2026 | 22/9/2026 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access… | |
| Aplazada | Crítica (9.3) | 0.61% | — | Comfast Cf-n1-sAI | 20/9/2026 | 24/9/2026 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.4) | 0.54% | — | Oisf Suricata | 20/9/2026 | 28/9/2026 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform. | |
| Analizada | Crítica (9.4) | 0.54% | — | Oisf Suricata | 20/9/2026 | 28/9/2026 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Openpanel Js-runtimeAI | 19/9/2026 | 2/10/2026 | OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Perl DBIAIPerl DBD DBMAIPerl MldbmAIPerl DBD GoferAI | 19/9/2026 | 22/9/2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Botiga PROAI | 19/9/2026 | 21/9/2026 | The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Totolink A3002muAI | 19/9/2026 | 22/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Crítica (9.1) | 0.73% | 💥 PoC | Incsub ForminatorAI | 19/9/2026 | 21/9/2026 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Crítica (9.1) | 0.68% | 💥 PoC | Bootstrapped WP Recipe MakerAI | 19/9/2026 | 21/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the… | |
| Aplazada | Crítica (9.8) | 3.9% | 💥 Exploit | Gravityforms Gravity FormsAI | 19/9/2026 | 21/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Totolink A3002muAI | 18/9/2026 | 21/9/2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Pendiente de análisis | Crítica (9.3) | 0.80% | — | Openshift ConsoleAI | 18/9/2026 | 8/10/2026 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial… | |
| Analizada | Crítica (9.1) | 0.42% | — | Oisf Suricata | 18/9/2026 | 29/9/2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks… | |
| Aplazada | Crítica (9.2) | 0.73% | — | CotontiAI | 18/9/2026 | 22/9/2026 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and… | |
| Pendiente de análisis | Crítica (9.3) | 0.76% | — | LightllmAI | 18/9/2026 | 22/9/2026 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of… | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | |
| Analizada | Crítica (9.9) | 0.47% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system. | |
| Analizada | Crítica (9.9) | 0.56% | — | IBM Guardium Data Protection | 18/9/2026 | 6/10/2026 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. |