Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

21.068 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.30%—Frappe27/8/202631/8/2026
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in frappe/desk/doctype/workspace_link/workspace_link.json, and _sanitize_content() in frappe/model/base_document.py skips…
AplazadaAlta (8.8)0.78%—Openwrt Luci-app-https-dns-proxyAI27/8/20261/9/2026
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
AplazadaAlta (8.6)0.36%—Mobile APP FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
AplazadaMedia (4.3)0.15%—Shopapper Mobile APP BuilderAI27/8/202628/8/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock…
AplazadaMedia (4.3)0.16%—ShopapperAI27/8/202628/8/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users'…
AplazadaAlta (7.1)0.42%—FrappeAI26/8/20269/9/2026
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another document through a Link field, the framework…
AplazadaBaja (3.5)0.28%—Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI26/8/202628/8/2026
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the…
AplazadaCrítica (9.1)0.46%—UI Unifi Network ApplicationAI26/8/202628/8/2026
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
AplazadaCrítica (9.1)1.3%—UI Unifi Network ApplicationAI26/8/202628/8/2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.
AplazadaAlta (8.8)0.10%—Apple ABRAI26/8/20263/9/2026
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AnalizadaMedia (5.5)0.14%—Apple IpadosApple Iphone OS25/8/202627/8/2026
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.
ModificadaMedia (5.5)0.17%💥 PoCApple Macos25/8/202614/9/2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
AnalizadaAlta (8.8)0.23%—Apple SafariApple IpadosApple Iphone OSApple Macos25/8/202627/8/2026
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
AnalizadaBaja (3.3)0.14%—Apple Iphone OS25/8/202631/8/2026
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.
Pendiente de análisisAlta (8.6)0.81%—Webkul QloappsAI25/8/202626/8/2026
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
Pendiente de análisisAlta (8.6)0.98%—Webkul QloappsAI25/8/202626/8/2026
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
AplazadaCrítica (10)0.60%—Miniorange Saml SSOAIMiniorange Saml SP Single Sign ON Login With AdfsAIMiniorange Saml SP Single Sign ON Saml SSO Login With Google AppsAIJoomlaAI25/8/20268/9/2026
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a…
AplazadaAlta (8.7)0.90%—Craterapp CraterAI25/8/202624/9/2026
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry…
AplazadaMedia (5.3)0.41%—Bookstackapp BookstackAI24/8/202624/9/2026
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the…
AplazadaAlta (8.6)0.53%—Woocommerce File ApprovalAI24/8/202624/8/2026
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
AplazadaBaja (3.7)0.41%—Apache Appsamurai UtilAI23/8/202626/8/2026
Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, each over a fresh Time::HiRes reading formatted to six decimal places, the running digest, and the process…
Pendiente de análisisCrítica (9.3)0.41%—Google Cloud Application IntegrationAI22/8/202631/8/2026
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.
AplazadaMedia (5.1)0.29%—Miraikan Assist APPAI21/8/202628/8/2026
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.