Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.35% | — | Hybrid ComposerAI | 4/6/2026 | 22/7/2026 | WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option… | |
| Modificada | Alta (8.8) | 1.9% | 💥 PoC | Getcomposer Composer | 15/4/2026 | 15/7/2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command()… | |
| Modificada | Alta (7.8) | 1.00% | 💥 PoC | Getcomposer Composer | 15/4/2026 | 15/7/2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping.… | |
| Aplazada | Media (5.3) | 0.27% | — | Tagdiv ComposerAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td-composer allows Code Injection.This issue affects tagDiv Composer: from n/a through <= 5.4.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Tagdiv ComposerAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Stored XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3. | |
| Aplazada | Alta (7.1) | 0.14% | — | Tagdiv ComposerAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | |
| Aplazada | Alta (7.5) | 0.39% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.1) | 0.22% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8. | |
| Aplazada | Alta (7.5) | 0.72% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory. | |
| Aplazada | Alta (7.2) | 0.88% | — | HPE Aruba Networking Fabric ComposerAI | 27/1/2026 | 17/6/2026 | Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Aplazada | Media (6.5) | 0.25% | — | Tagdiv ComposerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Advantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+1 | 12/1/2026 | 17/6/2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product… | |
| Analizada | Baja (1.3) | 0.45% | — | Getcomposer Composer | 30/12/2025 | 17/6/2026 | Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to… | |
| Aplazada | Media (6.5) | 0.16% | — | Live Composer Page BuilderAI | 24/12/2025 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Aplazada | Media (5.9) | 0.21% | — | Voidcoders Void-visual-whmcs-elementAIWpbakery Visual ComposerAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3. | |
| Aplazada | Alta (7.5) | 0.62% | — | Live ComposerAI | 21/12/2025 | 17/6/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.4) | 0.23% | — | Live ComposerAI | 17/12/2025 | 17/6/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Crítica (9) | 0.25% | — | ComposerAI | 2/12/2025 | 3/9/2026 | SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges. | |
| Aplazada | Alta (7.1) | 0.23% | — | Tagdiv ComposerAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Tagdiv Td-composerAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1. | |
| Analizada | Media (5.3) | 0.25% | — | Synchronize Composer.json With Contrib Modules Project Synchronize Composer.json With Contrib Modules | 10/10/2025 | 30/9/2026 | Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Thememakers Visual Content ComposerAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This issue affects ThemeMakers Visual Content Composer: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | Lambertgroup LBG Universal Video Player Addon Visual ComposerAIWpbakery Page BuilderAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for WPBakery Page Builder lbg-universal-video-player-addon-visual-composer allows Reflected XSS.This issue affects Universal Video Player - Addon for WPBakery Page Builder:… | |
| Aplazada | Media (6.5) | 0.17% | — | Visualcomposer Visual Composer Website BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through < 45.15.0. | |
| Aplazada | Alta (8.1) | 0.54% | — | Octagonwebstudio Premium Addons FOR KingcomposerAIKing-theme KingcomposerAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer premium-addons-for-kingcomposer allows PHP Local File Inclusion.This issue affects Premium Addons for KingComposer: from n/a through <= 1.1.1. |