Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

9651 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.31%—Mobyproject Buildkit21/7/202630/7/2026
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
AplazadaAlta (8.8)0.51%—Free Builder FOR ElementorAI21/7/202621/7/2026
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form…
AplazadaCrítica (9.8)0.71%—Whitestudio Easy Form BuilderAI21/7/202621/7/2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in…
AplazadaMedia (6.1)0.36%—Fuint Member Marketing SystemAI20/7/202621/7/2026
Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file
AnalizadaMedia (5.6)0.41%—Mobyproject Buildkit20/7/20265/8/2026
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
AplazadaCrítica (9.1)0.40%—Joomlack Page Builder CKAI20/7/202623/7/2026
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.
AplazadaMedia (6.9)0.43%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.
AplazadaAlta (8.7)0.41%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.
AplazadaMedia (5.1)0.42%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
AplazadaAlta (8.6)0.42%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output +…
AplazadaAlta (8.7)0.52%—Themexpert Quix Page BuilderAIJoomlaAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files.…
AplazadaAlta (8.9)0.53%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via…
AplazadaMedia (5.5)0.69%—Newpanjing SimpleuiAI19/7/202621/7/2026
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and…
AplazadaBaja (2.1)0.37%—Nextlevelbuilder GoclawAI19/7/202620/7/2026
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used.
AplazadaBaja (2.1)0.46%—Nextlevelbuilder GoclawAI18/7/202620/7/2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has…
AplazadaBaja (2.1)0.37%—Nextlevelbuilder GoclawAI18/7/202622/7/2026
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has…
AplazadaBaja (1.9)0.31%—Nextlevelbuilder GoclawAI18/7/202620/7/2026
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may…
AplazadaBaja (2.1)0.37%—Nextlevelbuilder GoclawAI18/7/202620/7/2026
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
AplazadaBaja (2.1)0.40%—Nextlevelbuilder GoclawAI18/7/202620/7/2026
A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from remote. The exploit has been publicly…
AplazadaBaja (2.1)0.40%—Nextlevelbuilder GoclawAI18/7/202621/7/2026
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The…
AnalizadaCrítica (9)0.57%—Delskayn RquickjsSurrealdb18/7/202613/8/2026
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
ModificadaMedia (6.5)0.37%—Redhat Build OF Keycloak17/7/202616/9/2026
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden…
ModificadaMedia (4.9)0.42%—Redhat Build OF Keycloak17/7/202616/9/2026
A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles…
ModificadaMedia (6.5)0.46%—Redhat Build OF Keycloak17/7/202616/9/2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are…
ModificadaMedia (4.3)0.34%—Redhat Build OF Keycloak17/7/202631/8/2026
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemption handler. This allows an attacker…