Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.17% | — | ComposerAI | 8/7/2026 | 10/7/2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during… | |
| Aplazada | Baja (3.3) | 0.31% | — | Docker ComposeAIRedisAIKeydbAIDragonflyAI+4 | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the… | |
| Aplazada | Media (5.3) | 0.42% | — | Premium Addons FOR KingcomposerAI | 30/6/2026 | 1/7/2026 | The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX handlers, both of which are exposed… | |
| Pendiente de análisis | Alta (7.8) | 0.55% | — | Mosaicml ComposerAI | 24/6/2026 | 25/6/2026 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Aplazada | Media (6.3) | 0.16% | — | HCL VerseAICompose-rich-editorAI | 19/6/2026 | 22/6/2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations. | |
| Analizada | Alta (8.7) | 0.92% | — | Hcltech Digital ExperienceHcltech Digital Experience Compose | 5/6/2026 | 23/7/2026 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. | |
| Analizada | Media (6.1) | 0.14% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | |
| Analizada | Media (6.1) | 0.15% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Hybrid ComposerAI | 4/6/2026 | 22/7/2026 | WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option… | |
| Modificada | Alta (8.8) | 1.9% | — | Getcomposer Composer | 15/4/2026 | 15/7/2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command()… | |
| Modificada | Alta (7.8) | 1.00% | — | Getcomposer Composer | 15/4/2026 | 15/7/2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping.… | |
| Aplazada | Media (5.3) | 0.27% | — | Tagdiv ComposerAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td-composer allows Code Injection.This issue affects tagDiv Composer: from n/a through <= 5.4.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Tagdiv ComposerAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Stored XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3. | |
| Aplazada | Alta (7.1) | 0.14% | — | Tagdiv ComposerAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | |
| Aplazada | Alta (7.5) | 0.39% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.1) | 0.22% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8. | |
| Aplazada | Alta (7.5) | 0.72% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory. | |
| Aplazada | Alta (7.2) | 0.88% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Aplazada | Media (6.5) | 0.25% | — | Tagdiv ComposerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | |
| Analizada | Alta (8.7) | 0.23% | — | Viafirma DocumentsViafirma Documents Compose | 12/1/2026 | 17/6/2026 | Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of… | |
| Modificada | Crítica (9.8) | 40% | — | Advantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+1 | 12/1/2026 | 17/6/2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product… | |
| Analizada | Baja (1.3) | 0.45% | — | Getcomposer Composer | 30/12/2025 | 17/6/2026 | Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to… | |
| Aplazada | Media (5.9) | 0.21% | — | Voidcoders Void-visual-whmcs-elementAIWpbakery Visual ComposerAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3. | |
| Aplazada | Media (6.5) | 0.16% | — | Live Composer Page BuilderAI | 24/12/2025 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Aplazada | Alta (7.5) | 0.62% | — | Live ComposerAI | 21/12/2025 | 17/6/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access… |