Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 332 respecto a la semana anterior
Críticas / altas1275▼ 217 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
8603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.50% | — | Nestjs Platform-fastifyAI | 22/6/2026 | 24/6/2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestjs/platform-fastify. When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the… | |
| Analizada | Media (5.9) | 0.53% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq | 22/6/2026 | 31/8/2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Tririga Application Platform | 22/6/2026 | 30/6/2026 | IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (8.3) | 0.30% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet… | |
| Modificada | Alta (8.8) | 0.11% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows… | |
| Aplazada | Baja (2.1) | 0.40% | — | Zhilink ADP Application Developer PlatformAI | 21/6/2026 | 22/6/2026 | A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.41% | — | Zhilink ADP Application Developer PlatformAI | 21/6/2026 | 22/6/2026 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has been made public and… | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Alta (8.6) | 0.46% | — | Hitachi Virtual Storage PlatformAI | 19/6/2026 | 29/9/2026 | Vulnerabilidad DoS en la interfaz iSCSI de 10G de Hitachi Virtual Storage Platform. Este problema afecta a Hitachi Virtual Storage Platform E990, E1090, E1090H: antes de DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, antes de DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, antes de DKCMAIN… | |
| Aplazada | Media (6.5) | 0.35% | — | MagicformAI | 18/6/2026 | 22/6/2026 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server. | |
| Aplazada | Media (4.9) | 0.34% | — | 10web Form MakerAI | 18/6/2026 | 18/6/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (4.9) | 0.34% | — | 10web Form MakerAI | 18/6/2026 | 18/6/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Crítica (9.8) | 0.48% | 💥 PoC | Registration Form FOR WoocommerceAI | 17/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | |
| Aplazada | Media (6.8) | 0.28% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 16/9/2026 | Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | |
| Aplazada | Crítica (9) | 0.40% | — | Sigmaforms PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Metform PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | |
| Aplazada | Media (4.3) | 0.24% | — | Metform PROAI | 17/6/2026 | 17/6/2026 | Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 17/6/2026 | 1/10/2026 | La vulnerabilidad de Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en QuantumCloud Conversational Forms for ChatBot permite Salto de Ruta. Este problema afecta a Conversational Forms for ChatBot: desde n/a hasta 1.1.8. | |
| Modificada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Deployment Library). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Modificada | Crítica (9) | 0.40% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base… | |
| Modificada | Alta (7.2) | 0.49% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Modificada | Alta (7.2) | 0.49% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise… | |
| Modificada | Alta (8.2) | 0.41% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager… | |
| Modificada | Alta (8.2) | 0.18% | — | Oracle Enterprise Manager Base Platform | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise… |