Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.48% | — | Snipeitapp Snipe-it | 10/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to… | |
| Analizada | Media (4.3) | 0.33% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent… | |
| Analizada | Media (4.8) | 0.29% | — | Snipeitapp Snipe-it | 10/7/2026 | 13/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user… | |
| Modificada | Alta (7.1) | 0.44% | — | Snipeitapp Snipe-it | 10/7/2026 | 14/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another… | |
| Analizada | Alta (7.7) | 0.39% | — | Snipeitapp Snipe-it | 10/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple… | |
| Analizada | Media (4.9) | 0.39% | — | Snipeitapp Snipe-it | 8/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API… | |
| Analizada | Baja (1.3) | 0.28% | — | Snipeitapp Snipe-it | 8/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the… | |
| Aplazada | Alta (8.5) | 0.58% | — | Postsnippets Post SnippetsAI | 25/6/2026 | 25/6/2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | |
| Analizada | Media (5.5) | 0.31% | — | Snipeitapp Snipe-it | 23/6/2026 | 26/6/2026 | Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`, `reports.view`, import, etc. The issue is patched in… | |
| Modificada | Alta (7.1) | 0.42% | — | Snipeitapp Snipe-it | 8/6/2026 | 21/8/2026 | Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag,… | |
| Aplazada | Media (4.4) | 0.36% | — | Postsnippets Post SnippetsAI | 29/5/2026 | 21/7/2026 | The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php`… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Analizada | Alta (7.1) | 0.25% | — | Snipeitapp Snipe-it | 26/5/2026 | 24/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1. | |
| Modificada | Alta (8.7) | 0.44% | — | Snipeitapp Snipe-it | 26/5/2026 | 24/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array,… | |
| Analizada | Media (5.4) | 0.33% | — | Snipeitapp Snipe-it | 26/5/2026 | 24/7/2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1. | |
| Analizada | Crítica (9.8) | 0.79% | — | Snipeitapp Snipe-it | 7/5/2026 | 17/6/2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component | |
| Aplazada | Media (6.4) | 0.32% | — | Text SnippetsAI | 22/4/2026 | 17/6/2026 | The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.50% | — | Snipeitapp Snipe-it | 14/4/2026 | 17/6/2026 | An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request. | |
| Aplazada | Media (5.4) | 0.23% | — | Snipeitapp Snipe-itAI | 13/4/2026 | 5/7/2026 | Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, to inject arbitrary JavaScript code via "Name" and "Surname" fields. The JavaScript code is executed whenever "Activity… | |
| Aplazada | Media (6.4) | 0.33% | — | Dsgvo Snippet FOR Leaflet MAP AND ITS ExtensionsAI | 26/3/2026 | 17/6/2026 | The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Crítica (9.9) | 0.31% | — | Themeisle Woody AD SnippetsAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1. | |
| Aplazada | Alta (8.5) | 0.23% | — | Postsnippets Post SnippetsAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12. | |
| Aplazada | Media (6.1) | 0.18% | — | Post SnippitsAI | 21/3/2026 | 17/6/2026 | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for saving, adding, and deleting snippets. This makes it possible for unauthenticated attackers to modify plugin settings… | |
| Analizada | Alta (8.7) | 0.47% | 💥 PoC | Snipeitapp Snipe-it | 6/3/2026 | 17/6/2026 | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By… | |
| Aplazada | Media (4.3) | 0.22% | — | Codesnippets Code SnippetsAI | 6/2/2026 | 17/6/2026 | The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force… |