Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.21%—Prestashop TotadministrativemandateAI31/7/202631/8/2026
PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.
AplazadaAlta (8.1)0.35%—Foroup Customer Rest APIAI30/7/202631/7/2026
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.
AplazadaMedia (6.5)0.34%—Foroup Customer Rest APIAI30/7/202631/7/2026
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.
Pendiente de análisisAlta (7.5)0.55%—IBM Enterprise Build OF QuarkusAIQuarkus RestAI30/7/202630/7/2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
AplazadaAlta (8.7)0.71%—Gladinet CentrestackAI30/7/202630/7/2026
CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of…
AplazadaAlta (8.8)0.32%—Gladinet CentrestackAI30/7/202630/7/2026
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared…
AplazadaAlta (8.7)0.49%—Gladinet CentrestackAI30/7/202630/7/2026
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint…
AplazadaAlta (8.7)0.37%—Microsoft WindowsAIGladinet CentrestackAI30/7/202631/7/2026
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to…
AplazadaMedia (6.9)0.43%—Gladinet CentrestackAI30/7/202630/7/2026
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint. Attackers can exploit the lack of input…
AplazadaCrítica (9.3)0.69%—Gladinet CentrestackAI30/7/202630/7/2026
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded…
Pendiente de análisisMedia (6.5)0.49%—Dogtag PKIAIApache TomcatAIRedhat ResteasyAI28/7/202628/7/2026
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to…
Pendiente de análisisMedia (6.8)0.25%—Gnome LibrestAI22/7/20261/9/2026
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random…
AplazadaCrítica (10)0.75%—Prestashop PS FacetedsearchAI17/7/202623/7/2026
PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal…
AplazadaAlta (8.7)0.46%—CapgoAISupabase PostgrestAI15/7/202615/7/2026
Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when…
AplazadaMedia (4.5)0.43%—PrestashopAI13/7/202613/7/2026
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported…
AplazadaAlta (8.7)0.56%—CapgoAISupabase PostgrestAI12/7/202613/7/2026
Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR,…
Pendiente de análisisMedia (5.9)0.31%—Drupal Clean RestfulAI10/7/202613/7/2026
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
AnalizadaAlta (7.5)0.49%—Openresty10/7/202614/7/2026
OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to upstream servers, constructing the header in the stream proxy protocol…
AplazadaAlta (7.1)0.43%—CapgoAIPostgrestAI10/7/202610/7/2026
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such…
AplazadaMedia (6.5)0.30%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header.…
AplazadaAlta (7.5)0.43%—Wpeverest Everest FormsAI9/7/20269/7/2026
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable…
AplazadaAlta (8.3)0.40%—Zope RestrictedpythonAI8/7/202610/7/2026
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments,…
AplazadaMedia (6.9)0.36%—CapgoAISupabase PostgrestAI8/7/20268/7/2026
Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only the public sb_publishable_* key. An unauthenticated attacker can probe organization existence and leak sensitive…
AplazadaAlta (8.7)0.43%—CapgoAISupabase PostgrestAI8/7/20268/7/2026
Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated access. Because the function accepts a caller-supplied user UUID without verifying it matches the authenticated user, an…
AplazadaMedia (5.5)0.69%—Jairiidriss Restaurant-website-php-mysqlAI4/7/20266/7/2026
A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried…
Orbitaley — Vulnerabilidades