Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
21.069 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.40% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's… | |
| Aplazada | Alta (7.1) | 0.45% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents without the required authorization. This issue is fixed in versions 15.110.0 and… | |
| Aplazada | Alta (8.6) | 0.26% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and capture the login token when a recipient… | |
| Aplazada | Media (5.1) | 0.41% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's private workspace and persistent script injection. This issue is fixed in… | |
| Aplazada | Media (6.3) | 0.22% | — | Insta InstinaknxserviceappAI | 6/8/2026 | 12/8/2026 | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of… | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 6/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dynamiapps Frontend AdminAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | DynamiappsAI | 6/8/2026 | 12/8/2026 | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Analizada | Alta (8.1) | 0.23% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 6/8/2026 | 10/8/2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it… | |
| Analizada | Alta (8.3) | 0.14% | 💥 PoC | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Safetipin Android ApplicationAI | 5/8/2026 | 1/10/2026 | Mi aplicación Safetipin para Android 5.2.1 contiene credenciales codificadas de forma rígida en el módulo de autenticación, lo que permite a atacantes remotos eludir la autenticación y obtener acceso no autorizado a cuentas de usuario a través de valores OTP predecibles. | |
| Aplazada | Alta (8.1) | 0.39% | — | Sirengps Android ApplicationAI | 5/8/2026 | 1/10/2026 | SirenGPS Aplicación Android 2.19.44 es vulnerable a control de acceso incorrecto. Un atacante autenticado puede manipular los parámetros de identificador de usuario para eludir los controles de autorización y obtener acceso de LECTURA y ESCRITURA no autorizado a la información personal de otros usuarios. La API no… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HCL Appscan PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Application Gateway Operator | 5/8/2026 | 10/8/2026 | IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Websphere Application Server | 5/8/2026 | 10/8/2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. | |
| Analizada | Media (4.3) | 0.19% | — | IBM Maximo Application Suite | 5/8/2026 | 10/8/2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 26/8/2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can read, edit, or delete another company's… | |
| Aplazada | Media (4.4) | 0.31% | — | Super Progressive WEB AppsAI | 5/8/2026 | 12/8/2026 | The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without… | |
| Aplazada | Alta (8.3) | 0.37% | — | Craterapp CraterAI | 5/8/2026 | 28/8/2026 | Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and… | |
| Aplazada | Media (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 5/8/2026 | 12/8/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… |