Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
14.266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.56% | 💥 PoC | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is… | |
| Aplazada | Alta (7.5) | 0.58% | 💥 PoC | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Media (6.9) | 0.74% | — | Maalfer MailerupAI | 18/8/2026 | 1/9/2026 | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Kainelabs YouzifyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Kaizencoders URL ShortifyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Brainstormforce Convert PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | |
| Aplazada | Media (5.5) | 0.43% | — | Phpgurukul Complaint Management SystemAI | 18/8/2026 | 20/8/2026 | A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Crítica (9.8) | 0.86% | — | Rainygao DocsysAI | 17/8/2026 | 31/8/2026 | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | |
| Aplazada | Crítica (9.8) | 0.60% | — | Brainformatik Crm+AI | 17/8/2026 | 9/9/2026 | The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL… | |
| Analizada | Alta (8.4) | 0.18% | — | Jetbrains Pycharm | 17/8/2026 | 10/9/2026 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | |
| Analizada | Media (4.4) | 0.18% | — | Jetbrains Pycharm | 17/8/2026 | 10/9/2026 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | |
| Analizada | Media (5.5) | 0.15% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | |
| Analizada | Media (6.2) | 0.17% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | |
| Analizada | Alta (7.8) | 0.19% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | |
| Analizada | Media (5.5) | 0.15% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | |
| Analizada | Media (6.3) | 0.15% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | |
| Analizada | Media (5.4) | 0.24% | — | Jetbrains Intellij Idea | 17/8/2026 | 11/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | |
| Analizada | Media (4.4) | 0.18% | — | Jetbrains Intellij Idea | 17/8/2026 | 1/9/2026 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects | |
| Analizada | Alta (8.1) | 0.35% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | |
| Analizada | Media (6.5) | 1.1% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | |
| Analizada | Media (6.5) | 0.34% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | |
| Analizada | Alta (8.2) | 0.32% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | |
| Analizada | Media (6.5) | 1.2% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | |
| Analizada | Media (4.3) | 0.27% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | |
| Analizada | Crítica (9.1) | 0.42% | — | Jetbrains Youtrack | 17/8/2026 | 15/9/2026 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |