Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
8603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 3.5% | 💥 Exploit | Divi Form BuilderAI | 2/7/2026 | 2/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is… | |
| Aplazada | Media (5.3) | 0.29% | — | EZ Form Calculator PremiumAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Advanced Contact Form 7 DBAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | |
| Aplazada | Media (6.5) | 0.43% | — | Crmperks Contact Form EntriesAI | 2/7/2026 | 2/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's… | |
| Aplazada | Media (5.3) | 0.58% | — | Crocoblock JetformbuilderAI | 2/7/2026 | 2/7/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve… | |
| Aplazada | Alta (7.5) | 0.60% | — | Ninjaforms Ninja Forms File UploadsAI | 2/7/2026 | 2/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a… | |
| Aplazada | Baja (2.7) | 0.28% | — | Fluentforms Fluent FormsAI | 2/7/2026 | 2/7/2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default… | |
| Aplazada | Media (6.5) | 0.34% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be… | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide… | |
| Aplazada | Media (5.4) | 0.23% | — | Divvydrive Information Technologies INC DivvydriveAI | 1/7/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1. | |
| Aplazada | Media (6.4) | 0.25% | — | Divvydrive Information Technologies INC DivvydriveAI | 1/7/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1. | |
| Aplazada | Alta (7.2) | 0.53% | — | NexformsAI | 1/7/2026 | 1/7/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.5) | 0.48% | — | Ninjaforms Ninja FormsAI | 1/7/2026 | 1/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers… | |
| Aplazada | Baja (3.1) | 0.21% | — | Fluentcrm Fluent FormsAI | 1/7/2026 | 1/7/2026 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. | |
| Aplazada | Alta (8.1) | 0.37% | — | Advancedformintegration Advanced Form IntegrationAI | 1/7/2026 | 1/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public… | |
| Aplazada | Media (4.3) | 0.25% | — | WS Form LiteAI | 1/7/2026 | 1/7/2026 | The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions, allowing authenticated users with subscriber-level access and above to modify the WS Form LITE WordPress plugin before 1.11.8's settings. | |
| Aplazada | Media (6.4) | 0.42% | — | Kaliforms Kali FormsAI | 1/7/2026 | 1/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.60% | — | WpformsAI | 1/7/2026 | 1/7/2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name… | |
| Pendiente de análisis | Media (5.6) | 0.39% | — | Solarwinds Database Performance AnalyzerAI | 30/6/2026 | 2/7/2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Alta (7.5) | 0.45% | — | IBM Infosphere Information Server | 30/6/2026 | 2/7/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. | |
| Modificada | Media (4.3) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 30/6/2026 | 5/8/2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific… | |
| Aplazada | Media (5.9) | 0.24% | — | KaliformsAI | 30/6/2026 | 30/6/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's… | |
| Modificada | Media (6.2) | 0.20% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit | 29/6/2026 | 28/9/2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Reputeinfosystems ArformsAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Paid Videochat Turnkey Site PerformerAI | 29/6/2026 | 29/6/2026 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. |