Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
8603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Baptism Information Management SystemAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.47% | — | Hanwang E-face General Management PlatformAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.3) | 0.35% | — | Hitachi Virtual Storage Platform E390AIHitachi Virtual Storage Platform E590AIHitachi Virtual Storage Platform E790AIHitachi Virtual Storage Platform E990AI+23 | 29/6/2026 | 29/6/2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H,… | |
| Aplazada | Media (6.8) | 0.38% | — | Hitachi Storage NavigatorAIHitachi Virtual Storage PlatformAIHitachi DkcmainAIHitachi SVPAI | 29/6/2026 | 29/9/2026 | Vulnerabilidad de exposición de información en Hitachi Storage Navigator. Este problema afecta a Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: antes de DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, antes de DKCMAIN Ver. 90-08-86-00/00, SVP Ver. 90-08-86/00; Hitachi… | |
| Aplazada | Baja (3.7) | 0.13% | — | Hitachi Virtual Storage Platform ONE BlockAI | 29/6/2026 | 29/9/2026 | Falta de validación para la actualización de firmware en Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. Este problema afecta a Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: antes de DKCMAIN A3-04-21-40/00, ESM A3-04-21/00. | |
| Aplazada | Media (5.3) | 0.49% | — | Basixonline Nex-formsAI | 27/6/2026 | 29/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Toolset FormsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | QuformAI | 26/6/2026 | 26/6/2026 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Gutenverse FormAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Buddyboss PlatformAIPHPAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | |
| Aplazada | Alta (7.7) | 0.18% | — | Parseplatform Parse ServerAI | 25/6/2026 | 26/6/2026 | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based… | |
| Analizada | Alta (7.7) | 0.18% | — | Parseplatform Parse-server | 25/6/2026 | 30/7/2026 | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code. | |
| Aplazada | Media (6.3) | 0.37% | — | Huly PlatformAI | 25/6/2026 | 14/7/2026 | Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate… | |
| Aplazada | Alta (7.1) | 0.25% | — | Incsub ForminatorAI | 25/6/2026 | 25/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Gravityforms BookingAI | 25/6/2026 | 25/6/2026 | The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpforms WP Forms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Wpforms ConnectorAI | 24/6/2026 | 25/6/2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that… | |
| Aplazada | Media (5.3) | 0.40% | — | Advanced Contact Form 7 Compact DBAI | 24/6/2026 | 25/6/2026 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and… | |
| Aplazada | Alta (7.2) | 0.32% | — | Reputeinfosystems ArformsAI | 24/6/2026 | 25/6/2026 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Pega PlatformAI | 23/6/2026 | 6/10/2026 | Versiones de Pega Platform 8.3.0 hasta Infinity 25.1.2 se ven afectadas por una debilidad de autorización que puede permitir a usuarios autenticados acceder a ciertos datos adicionales a través de URLs manipuladas. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpkube Simple Basic Contact FormAI | 23/6/2026 | 23/6/2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or… | |
| Modificada | Media (6.5) | 0.60% | — | Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/6/2026 | 7/10/2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.… |