Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 225 respecto a la semana anterior
Críticas / altas1331▼ 100 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
21.648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.49% | — | Pallets Community Flask Security TOOAI | 20/7/2026 | 23/7/2026 | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that belongs to a different user. If an attacker can operate an already-authenticated but stale victim session, they can… | |
| Aplazada | Media (4.3) | 0.28% | — | Gobito Informatics Technologies Corporate Training Management SystemAI | 20/7/2026 | 21/7/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64. | |
| Aplazada | Alta (8.7) | 0.37% | — | CodeigniterAICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` →… | |
| Aplazada | Media (6.5) | 0.48% | — | CodeigniterAICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and… | |
| Aplazada | Media (5.4) | 0.24% | — | Codeigniter 4AICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently… | |
| Aplazada | Media (4.8) | 0.11% | — | Fantomas42 Django-blog-zinniaAI | 19/7/2026 | 20/7/2026 | A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The… | |
| Aplazada | Baja (1.3) | 1.2% | — | Liumenxuan04 MinicodeAI | 18/7/2026 | 20/7/2026 | A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be… | |
| Aplazada | Crítica (9.8) | 0.78% | — | CodeigniterAI | 17/7/2026 | 23/7/2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the client-provided filename extension. As a result, an uploaded file named shell.php containing GIF-like content could… | |
| Analizada | Crítica (9.8) | 0.46% | — | IBM AgenticsIBM DB2 Genius HUB | 17/7/2026 | 11/8/2026 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions. | |
| Aplazada | Media (6.4) | 0.26% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any capability check, nonce verification, or… | |
| Aplazada | Media (4.3) | 0.66% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary… | |
| Aplazada | Media (4.3) | 0.28% | — | Ninja Forms Excel ExportAI | 17/7/2026 | 17/7/2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL… | |
| Pendiente de análisis | Media (5) | 0.21% | — | Canonical Ubuntu PRO ClientAI | 16/7/2026 | 16/7/2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying… | |
| Pendiente de análisis | Crítica (9) | 0.53% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the… | |
| Aplazada | Alta (8.8) | 0.44% | — | Unitedover DigitsAI | 16/7/2026 | 16/7/2026 | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.8) | 1.5% | 💥 Exploit | Miniorange Saml Single Sign ON SSOAI | 16/7/2026 | 7/8/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the… | |
| Aplazada | Alta (8.8) | 0.46% | — | Github ActionsAIMaaassistantarknightsAI | 15/7/2026 | 12/8/2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork… | |
| Aplazada | Alta (8.6) | 0.55% | — | Adonisjs BodyparserAIPoppinss UtilsAILodashAI | 15/7/2026 | 16/7/2026 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain… | |
| Aplazada | Alta (8.5) | 0.15% | — | Nixpkgs MysqlAINixpkgs Percona-serverAI | 15/7/2026 | 15/7/2026 | Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in… | |
| Analizada | Alta (8.4) | 0.63% | — | Lightningai Pytorch Lightning | 15/7/2026 | 8/10/2026 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True… | |
| Aplazada | Alta (7.7) | 0.45% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity… | |
| Aplazada | Media (5.8) | 0.40% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP… | |
| Aplazada | Media (6.9) | 0.66% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the… | |
| Aplazada | Alta (8.3) | 0.25% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token… |