Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2814▼ 267 respecto a la semana anterior
Críticas / altas1316▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

8610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.11%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability.
Pendiente de análisisAlta (8.3)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability.
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.
Pendiente de análisisMedia (6.9)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation
AplazadaCrítica (9)0.54%—Vcluster PlatformAI14/5/202617/6/2026
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the…
AnalizadaMedia (5.3)0.21%—Verint Verba Collaboration Compliance AND Quality Management Platform14/5/202617/6/2026
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,…
AplazadaMedia (6.8)0.40%—IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI14/5/202617/6/2026
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0.
AplazadaAlta (8.8)0.24%—Appyap Technology AND Information INC Yaay Social Media APPAI14/5/20267/10/2026
Omisión de autorización a través de una vulnerabilidad de clave controlada por el usuario en la aplicación Yaay Social Media de APPYAP Technology and Information Inc. permite acceder a funcionalidades no restringidas adecuadamente por las ACL. Este problema afecta a la aplicación Yaay Social Media: desde la versión…
AplazadaMedia (5.3)0.40%—MW WP FormAI14/5/202617/6/2026
The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from…
AplazadaAlta (8.2)0.38%—Fluentforms Fluent FormsAI14/5/202617/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for…
AplazadaAlta (8.2)0.37%—Fluentforms Fluent FormsAI14/5/202617/6/2026
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This…
AplazadaCrítica (9.1)0.33%💥 PoCNearform Fast-jwtAI13/5/202617/6/2026
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an empty string (''),…
AplazadaBaja (3.8)0.14%—Arqit Symmetric KEY Agreement PlatformAI13/5/202617/6/2026
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
AplazadaMedia (5.3)0.33%—Arqit Symmetric KEY Agreement PlatformAIKeycloakAI13/5/202617/6/2026
Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03.
AplazadaAlta (8.7)0.34%—Arqit Symmetric KEY Agreement PlatformAI13/5/202617/6/2026
Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03.
Pendiente de análisisMedia (6.3)0.34%—Teamviewer DEX Platform On-premisesAI13/5/202617/6/2026
A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution…
AnalizadaMedia (5.1)0.18%—Agpt Autogpt Platform13/5/20267/10/2026
AutoGPT es una plataforma que permite a los usuarios crear, desplegar y gestionar agentes de inteligencia artificial continuos que automatizan flujos de trabajo complejos. En AutoGPT, el proceso de ejecución se registra en la consola (stdout/stderr) y se despliega en modo contenedor, que es capturado automáticamente…
AplazadaMedia (6.4)0.35%—Fluentforms Fluent FormsAI13/5/202617/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it…
AnalizadaAlta (8.8)0.86%—Microsoft Data Formulator12/5/202617/6/2026
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.09%—Intel Connectivity Performance Suite12/5/202621/7/2026
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
AnalizadaBaja (2.1)0.30%—Parseplatform Parse-server12/5/202617/6/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session…
AplazadaAlta (8.5)0.36%—Aman Views Views FOR Wpforms LiteAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6.
AplazadaAlta (8.5)0.36%—Aman Views FOR Ninja FormsAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views &#8211; Display &amp; Edit Ninja…
Pendiente de análisisCrítica (9.2)0.41%—Google Cloud Alloydb FOR PostgresqlAIHashicorp TerraformAI12/5/202617/6/2026
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database. Exploitation required network access to the…