Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

9646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (0.6)0.10%—QT QuickAI23/9/202624/9/2026
Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.
Pendiente de análisisCrítica (9.8)0.42%—Apache BuildstreamAI23/9/202623/9/2026
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of…
AplazadaAlta (8.6)0.27%—Jet-form-builder-stripe-gatewayAI23/9/202623/9/2026
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
Pendiente de análisisAlta (8.7)1.9%—Amazon S2n-quicAI22/9/202623/9/2026
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To…
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaMedia (6.5)0.37%—Ph7software Ph7builderAI22/9/20265/10/2026
pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this…
AplazadaMedia (6.5)0.50%—Ph7software Ph7builderAI22/9/202623/9/2026
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote…
AplazadaMedia (4.7)0.27%—Vaxilu X-uiAI22/9/202622/9/2026
A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the…
AplazadaAlta (8.8)0.30%—Vaxilu X-uiAI22/9/202625/9/2026
A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The…
AplazadaAlta (7.1)0.56%—Wptablebuilder WP Table BuilderAI22/9/202622/9/2026
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never…
AplazadaAlta (8.8)0.57%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (6.5)0.53%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the…
AplazadaMedia (4.8)0.29%—Vaxilu X-uiAI21/9/202622/9/2026
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password,…
AplazadaAlta (7.6)0.32%—Vaxilu X-uiAI21/9/202622/9/2026
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback…
Pendiente de análisisMedia (5.5)0.13%—Dell Command Integration Suite FOR System CenterAI21/9/202622/9/2026
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
AplazadaAlta (7.2)0.39%—Mdmag Quill FormsAI19/9/202621/9/2026
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (4.3)0.21%—PDF Builder FOR WoocommerceAI19/9/202621/9/2026
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (5.5)0.23%—Crocoblock JetformbuilderAI19/9/202621/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server…
AplazadaMedia (4.3)0.18%—Presscustomizr Nimble Page BuilderAI19/9/202621/9/2026
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts…
AplazadaMedia (6.4)0.33%—Liquidweb WpcompleteAI19/9/202621/9/2026
The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…