Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.5) | 0.39% | 💥 PoC | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component… | |
| Analizada | Alta (8.9) | 0.37% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the… | |
| Analizada | Alta (8.6) | 0.33% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A… | |
| Analizada | Media (6.9) | 0.24% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata… | |
| Analizada | Media (6.9) | 0.21% | — | Balbooa Forms | 29/9/2026 | 6/10/2026 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session… | |
| Pendiente de análisis | Baja (3.7) | 0.23% | — | KeycloakAI | 28/9/2026 | 28/9/2026 | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider… | |
| Aplazada | Media (5.5) | 0.28% | — | Athlon1600 Youtube-downloaderAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.1) | 0.32% | — | Nezha DashboardAI | 27/9/2026 | 28/9/2026 | Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their… | |
| Aplazada | Alta (8.8) | 0.28% | — | Download ManagerAI | 27/9/2026 | 28/9/2026 | The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects… | |
| En análisis | Crítica (9.3) | 0.38% | 💥 PoC | Joomlaboat Youtube GalleryAI | 26/9/2026 | 29/9/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| Aplazada | Alta (7.1) | 0.32% | — | StoatchatAI | 26/9/2026 | 28/9/2026 | stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery… | |
| Aplazada | Alta (8.3) | 0.24% | — | StoatchatAI | 26/9/2026 | 30/9/2026 | stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate… | |
| Aplazada | Media (6.9) | 0.26% | — | StoatchatAI | 26/9/2026 | 30/9/2026 | stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between registered and unregistered email addresses by comparing error location fields returned from POST /api/auth/session/login… | |
| Aplazada | Alta (8.8) | 0.40% | — | StoatchatAI | 26/9/2026 | 28/9/2026 | January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via… | |
| Aplazada | Alta (7.1) | 0.31% | — | StoatchatAI | 26/9/2026 | 28/9/2026 | stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until… | |
| Aplazada | Media (5.3) | 0.23% | — | StoatchatAI | 26/9/2026 | 30/9/2026 | stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists and length limits to create reserved-name lookalikes, embed… | |
| Pendiente de análisis | Media (5.3) | 0.33% | 💥 PoC | Wikimedia UploadwizardAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Payloadcms Storage-vercel-blobAI | 25/9/2026 | 30/9/2026 | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the… | |
| Analizada | Media (4.5) | 0.28% | — | Broadcom Rabbitmq Server | 25/9/2026 | 6/10/2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management UI was enabled. Exploitation requires an attacker with queue… | |
| Aplazada | Crítica (9.8) | 0.27% | — | Friendsofflarum OauthAI | 25/9/2026 | 30/9/2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When… | |
| Aplazada | Alta (7.5) | 0.30% | — | Wellav WES Emergency Broadcast TerminalAI | 25/9/2026 | 30/9/2026 | An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function | |
| Pendiente de análisis | Media (6.6) | 0.24% | — | KeycloakAI | 25/9/2026 | 26/9/2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | KeycloakAI | 25/9/2026 | 25/9/2026 | Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard Token Exchange V2 feature does not check for this certificate. This allows an… | |
| Aplazada | Alta (7.5) | 0.64% | — | Goauthentik AuthentikAI | 24/9/2026 | 29/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or… | |
| Aplazada | Alta (7.4) | 0.27% | — | Goauthentik AuthentikAI | 24/9/2026 | 24/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML… |