Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
9810 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.30% | — | Mongodb PHP DriverAI | 24/9/2026 | 24/9/2026 | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database… | |
| Aplazada | Alta (8.1) | 0.40% | — | PhpmyfaqAI | 24/9/2026 | 29/9/2026 | phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a valid or brute-forced six-digit TOTP code without first authenticating with… | |
| Aplazada | Alta (8.2) | 0.24% | — | PhpmyfaqAI | 24/9/2026 | 24/9/2026 | phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ… | |
| Aplazada | Media (6.3) | 0.30% | — | Python-hyper HpackAI | 23/9/2026 | 30/9/2026 | hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix is available in python-hyper/hpack v4.2.0 to… | |
| Aplazada | Alta (8.1) | 0.64% | 💥 PoC | EthpressAI | 23/9/2026 | 24/9/2026 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a… | |
| Aplazada | Alta (8.1) | 0.13% | — | Publishpress CapabilitiesAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. | |
| En análisis | Alta (7.4) | 0.50% | — | Watchguard Authpoint GatewayAI | 23/9/2026 | 24/9/2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | |
| Aplazada | Alta (7.5) | 0.30% | — | Rename WP Login PHP TO Anything YOU WantAI | 23/9/2026 | 23/9/2026 | The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (7.7) | 0.39% | — | MispAICakephpAI | 22/9/2026 | 22/9/2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: No component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or… | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | HP Support AssistantAI | 22/9/2026 | 29/9/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Aplazada | Media (6.9) | 0.27% | — | MispAICakephpAI | 22/9/2026 | 22/9/2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's… | |
| Pendiente de análisis | Media (5.3) | 0.35% | — | SAP Fiori LaunchpadAI | 21/9/2026 | 22/9/2026 | SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive… | |
| Aplazada | Media (5.2) | 0.23% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page. | |
| Aplazada | Media (5.8) | 0.21% | — | Cutephp CutenewsAI | 21/9/2026 | 25/9/2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter. | |
| Aplazada | Media (5.8) | 0.22% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php. | |
| Aplazada | Crítica (9.1) | 0.27% | — | Cutephp CutenewsAI | 21/9/2026 | 24/9/2026 | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | |
| Aplazada | Media (6.1) | 0.34% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>). | |
| Aplazada | Alta (7.2) | 0.53% | — | Cutephp CutenewsAI | 21/9/2026 | 22/9/2026 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell. | |
| Aplazada | Baja (2.1) | 0.49% | — | Olivier-ls Php-ftsAI | 20/9/2026 | 22/9/2026 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The manipulation leads to incorrect comparison. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2) | 0.42% | — | Olivier-ls Php-ftsAI | 19/9/2026 | 21/9/2026 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The… | |
| Pendiente de análisis | Alta (8.1) | 0.44% | — | IBM MQAIHPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data. | |
| Pendiente de análisis | Alta (8.1) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values. | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | IBM MQ FOR HPE NonstopAI | 18/9/2026 | 22/9/2026 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data. |