Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2826▼ 248 respecto a la semana anterior
Críticas / altas1321▼ 176 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
8604 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | CformsiiAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Feuerhamster MailformAI | 15/6/2026 | 17/6/2026 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Aplazada | Media (5.1) | 0.22% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts… | |
| Aplazada | Alta (8.8) | 0.24% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL… | |
| Aplazada | Alta (8.8) | 0.30% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter… | |
| Aplazada | Media (5.4) | 0.27% | — | Codepeople Form Builder CPAI | 15/6/2026 | 21/7/2026 | El plugin de WordPress Form Builder CP anterior a la versión 1.2.47 no sanea correctamente un valor de configuración de formulario antes de almacenarlo y usarlo como parte de una ejecución de script del lado del cliente, permitiendo a usuarios autenticados con acceso de nivel Editor o superior realizar ataques de… | |
| Aplazada | Baja (2.1) | 0.20% | — | Hcengineering Huly PlatformAI | 15/6/2026 | 24/7/2026 | Una vulnerabilidad fue encontrada en hcengineering Huly Platform hasta 0.7.0. Afectada por esta vulnerabilidad es la función getAccountInfo del archivo server/account/src/operations.ts del componente User Information Handler. La manipulación resulta en autorización indebida. El ataque puede ser lanzado remotamente. El… | |
| Aplazada | Baja (2.1) | 0.21% | — | Hcengineering Huly PlatformAI | 15/6/2026 | 24/7/2026 | Una vulnerabilidad ha sido encontrada en hcengineering Huly Platform hasta 0.7.0. Afectada es la función getMailboxSecret del archivo server/account/src/operations.ts del componente RPC Interface. La manipulación lleva a controles de acceso inadecuados. El ataque puede ser iniciado remotamente. El exploit ha sido… | |
| Aplazada | Media (6.9) | 0.48% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client by protectedFields,… | |
| Aplazada | Media (5.9) | 0.43% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through the /login and /verifyPassword endpoints.… | |
| Aplazada | Baja (2.1) | 0.49% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. poc.svg.). The… | |
| Aplazada | Alta (8.7) | 0.41% | — | Naxclow PlatformAI | 12/6/2026 | 17/6/2026 | The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that… | |
| Aplazada | Media (6.9) | 0.60% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express middleware against… | |
| Aplazada | Media (6.9) | 0.51% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded in GraphQL validation-error messages.… | |
| Aplazada | Alta (8.7) | 0.91% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that… | |
| Aplazada | Alta (8.7) | 0.44% | — | Naxclow PlatformAI | 12/6/2026 | 17/6/2026 | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device… | |
| Pendiente de análisis | Alta (8.7) | 0.67% | — | Form-dataAI | 12/6/2026 | 11/9/2026 | form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters.… | |
| Aplazada | Alta (8.7) | 0.35% | — | Global IT Informatics Services INC WeollAI | 12/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33. | |
| Aplazada | Media (6.9) | 0.31% | — | Hepta Platforms HeptabaseAI | 12/6/2026 | 29/9/2026 | Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Aplazada | Crítica (9.9) | 0.34% | — | Basarsoft Information Technologies INC RotabanAI | 11/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003. | |
| Aplazada | Crítica (9.8) | 0.45% | 💥 PoC | Soagen Informatics Technologies Software AND Consulting ApinizerAI | 11/6/2026 | 17/6/2026 | Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6. | |
| Aplazada | Media (5.4) | 0.18% | — | Themehunk Contact Form AND Lead Form Elementor BuilderAI | 11/6/2026 | 26/9/2026 | Vulnerabilidad de autorización faltante en ThemeHunk Contact Form & Lead Form Elementor Builder permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Contact Form & Lead Form Elementor Builder: desde n/a hasta 1.8.4. | |
| Modificada | Alta (7.5) | 0.99% | — | Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+2 | 10/6/2026 | 9/9/2026 | JavaScript Cookie es una API de JavaScript para manejar cookies, del lado del cliente. Antes de la versión 3.0.7, la función auxiliar interna assign() de js-cookie copia propiedades con for...in + asignación simple. Cuando el objeto fuente es producido por JSON.parse, el miembro __proto__ del objeto JSON es una… |