Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
–

400.296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)———1/10/20261/10/2026
Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
AplazadaAlta (8.6)———1/10/20261/10/2026
Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
AplazadaAlta (7.1)———1/10/20261/10/2026
Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
AplazadaAlta (7.5)———1/10/20261/10/2026
A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
AplazadaAlta (7.4)———1/10/20261/10/2026
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
AplazadaMedia (5.9)———1/10/20261/10/2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
AplazadaMedia (5.9)———1/10/20261/10/2026
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
AnalizadaMedia (5.5)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
AnalizadaMedia (5.4)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
AnalizadaMedia (4.3)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
AnalizadaMedia (6.6)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
AnalizadaAlta (8.1)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
En análisisMedia (6.5)———1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
AnalizadaMedia (6.5)——Jetbrains Youtrack1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
En análisisAlta (7.2)———1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
En análisisBaja (2)———1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
En análisisAlta (7.1)———1/10/20261/10/2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
AplazadaAlta (7.2)———1/10/20261/10/2026
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.2)———1/10/20261/10/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)———1/10/20261/10/2026
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (6.4)———1/10/20261/10/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)———1/10/20261/10/2026
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated…
AplazadaAlta (7.2)———1/10/20261/10/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (6.4)———1/10/20261/10/2026
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (6.1)———1/10/20261/10/2026
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…