Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
9651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 1.1% | — | Louisho5 PicobotAI | 14/7/2026 | 14/7/2026 | A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit has been made public and could be used.… | |
| Aplazada | Baja (2.1) | 0.40% | — | Louisho5 PicobotAI | 14/7/2026 | 15/7/2026 | A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/tools/web.go of the component web Tool. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.43% | — | Louisho5 PicobotAI | 14/7/2026 | 14/7/2026 | A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesystem.go of the component Workspace Handler. Executing a manipulation can lead to link following. It is possible to launch the attack remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.42% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 14/7/2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.43% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 15/7/2026 | A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_bridge.go of the component ACP ToolBridge Workspace Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.48% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 14/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 15/7/2026 | A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery.… | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | SAP CRM Webclient UIAI | 14/7/2026 | 14/7/2026 | SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP UI5AI | 14/7/2026 | 14/7/2026 | setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable… | |
| Aplazada | Alta (7.1) | 0.25% | — | Funnelkit Funnel BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8. | |
| Aplazada | Media (6.5) | 0.22% | — | Envision Page BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision Envision Page Builder envision-page-builder allows DOM-Based XSS.This issue affects Envision Page Builder: from n/a through <= 0.22. | |
| Aplazada | Alta (7.1) | 0.25% | — | Tagdiv Opt-in BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Villatheme Bopo Woocommerce Product Bundle BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/7/2026 | 21/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8. | |
| Aplazada | Media (6.5) | 0.33% | — | Edgarrojas Extra Product Options Builder FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167. | |
| Aplazada | Media (6.5) | 0.27% | — | Inspireui Mstore APIAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themify BuilderAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4. | |
| Aplazada | Baja (1.9) | 0.17% | — | Makafeli N8n-workflow-builderAI | 13/7/2026 | 15/7/2026 | A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation of the argument filePath leads to path traversal. An attack has to be approached locally. The exploit is publicly available… | |
| Aplazada | Media (5.3) | 0.58% | — | Stylemixthemes Cost Calculator BuilderAI | 11/7/2026 | 13/7/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded… | |
| Aplazada | Media (6.4) | 0.35% | — | Themify BuilderAI | 11/7/2026 | 15/7/2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.4) | 0.33% | — | Themify BuilderAI | 11/7/2026 | 13/7/2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.35% | — | Starboard Suite Reservation CalendarsAI | 11/7/2026 | 29/9/2026 | El plugin Starboard Suite Reservation Calendars para WordPress es vulnerable a cross-site scripting almacenado a través de atributos de shortcode en el shortcode [starboard-suite-lightbox] en todas las versiones hasta la 3.1.4, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto… | |
| Aplazada | Alta (8.8) | 0.44% | — | Wpgridbuilder WP Grid BuilderAI | 11/7/2026 | 13/7/2026 | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.23% | — | Ademarco UI Patterns | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. | |
| Analizada | Media (4.8) | 0.12% | — | Victorkane Salesforce Suite | 10/7/2026 | 6/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. |