Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

21.034 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.9)0.64%—Plone App.portletsAI22/9/202623/9/2026
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro…
AplazadaAlta (7.2)0.43%—Ljapps WP Yelp Review SliderAI22/9/202622/9/2026
The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.8)0.65%—Openwrt Luci-app-advanced-rebootAI21/9/202624/9/2026
luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in…
AplazadaAlta (8.8)0.49%—Openwrt Luci-app-adblock-fastAI21/9/202629/9/2026
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as…
Pendiente de análisisAlta (7.1)0.30%—Canva Mobile APPAI21/9/202621/9/2026
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
AplazadaMedia (5.5)0.51%—Noncegeek Dim-sum-appAI20/9/202621/9/2026
A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been…
AplazadaAlta (7.1)0.42%—Frappe ErpnextAI20/9/202621/9/2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to…
AplazadaMedia (4.3)0.33%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered…
AplazadaBaja (2.7)0.32%—Meowapps Meow GalleryAI20/9/202621/9/2026
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and…
AplazadaMedia (6.5)0.15%—Meowapps Meow GalleryAI20/9/202621/9/2026
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose…
AplazadaAlta (8.8)0.52%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered…
AplazadaMedia (5.4)0.36%💥 PoCSmartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email…
AplazadaAlta (7.1)0.55%—Qloapps QloapsAI19/9/202622/9/2026
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including…
AplazadaMedia (6.5)0.47%—Easyappointments Easy AppointmentsAI19/9/202621/9/2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers…
AplazadaMedia (6.4)0.20%—AppmysiteAI19/9/202621/9/2026
The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via save_ams_license_key AJAX Handler in all versions up to, and including, 3.15.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.8)0.22%—Online Scheduling AND Appointment Booking SystemAI19/9/202621/9/2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages…
AplazadaCrítica (9.1)0.68%💥 PoCBootstrapped WP Recipe MakerAI19/9/202621/9/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the…
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Pendiente de análisisMedia (6.5)0.38%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Pendiente de análisisBaja (3.7)0.26%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
Pendiente de análisisMedia (5.3)0.30%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Pendiente de análisisMedia (5.3)0.30%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.