Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 87 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Miniorange OTP VerificationAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | |
| Aplazada | Baja (1.3) | 0.33% | — | Unitedbyai DroidclawAI | 27/7/2026 | 28/7/2026 | A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is… | |
| Aplazada | Crítica (9.1) | 1.2% | 💥 Exploit | EasyappointmentsAICodeigniterAI | 27/7/2026 | 30/7/2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema… | |
| Aplazada | Media (6.5) | 0.22% | — | Photonic Gallery AND Lightbox FOR Flickr Smugmug AND OthersAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | |
| Aplazada | Alta (8.7) | 1.1% | — | Nitroshare DesktopAI | 27/7/2026 | 28/7/2026 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit… | |
| Aplazada | Media (6.3) | 0.39% | 💥 PoC | TastyigniterAI | 27/7/2026 | 27/7/2026 | A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator… | |
| Aplazada | Crítica (9.8) | 0.83% | 💥 PoC | Realtyna Organic IDXAIRealtyna WPL Real EstateAI | 27/7/2026 | 27/7/2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it… | |
| Aplazada | Crítica (9.3) | 0.56% | — | Tycon Systems Tpdin Monitor Web2AI | 24/7/2026 | 4/9/2026 | The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can… | |
| Aplazada | Media (5.3) | 0.19% | — | Tycon Systems Tpdin-monitor-web2AI | 24/7/2026 | 4/9/2026 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other… | |
| Aplazada | Media (5.1) | 0.31% | — | Milkdown Preset CommonmarkAITennisconnect ComponentsAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The… | |
| Analizada | Media (6.5) | 0.10% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected. | |
| Analizada | Alta (8.8) | 0.53% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the… | |
| Analizada | Alta (8.8) | 0.53% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation. | |
| Analizada | Media (5) | 0.25% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks. | |
| Analizada | Media (6.5) | 0.38% | — | Devolutions Powershell Universal | 24/7/2026 | 29/7/2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. | |
| Analizada | Media (5.3) | 0.91% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the… | |
| Analizada | Alta (7.5) | 1.0% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to… | |
| Analizada | Alta (7.5) | 1.0% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users… | |
| Analizada | Alta (8.8) | 0.53% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over… | |
| Analizada | Media (6.5) | 0.69% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP… | |
| Analizada | Alta (7.5) | 0.48% | — | Apache Nimble | 24/7/2026 | 27/7/2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured… | |
| Aplazada | Media (4.9) | 0.51% | — | Ninjaforms Ninja FormsAI | 24/7/2026 | 24/7/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Sunnet Corporate Training Management SystemAI | 24/7/2026 | 28/7/2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a… | |
| Aplazada | Media (6.4) | 0.34% | — | Wpmanageninja Fluent SupportAI | 24/7/2026 | 24/7/2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.78% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 30/7/2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. |