Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
8610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.49% | — | Forms RBAI | 12/5/2026 | 17/6/2026 | The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to read form… | |
| Aplazada | Media (4.3) | 0.36% | — | Coinbase Commerce FOR Contact Form 7AI | 12/5/2026 | 17/6/2026 | The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce verification in the save_settings() function, which is registered on the admin_post_cccf7_save_settings hook. This… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | SAP Application Server AbapAISAP NetweaverAISAP Abap PlatformAI | 12/5/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution.… | |
| Pendiente de análisis | Media (5.4) | 0.12% | — | SAP Businessobjects Business Intelligence PlatformAI | 12/5/2026 | 17/6/2026 | Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Alta (7.7) | 0.45% | — | Getgrav FormAI | 11/5/2026 | 17/6/2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`,… | |
| Aplazada | Media (5.4) | 0.26% | — | Getgrav GravAIGetgrav FormAI | 11/5/2026 | 17/6/2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Twig |raw filter in the admin panel, bypassing the global autoescape… | |
| Aplazada | Alta (7.5) | 0.64% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url. | |
| Aplazada | Media (6.1) | 0.24% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application. | |
| Aplazada | Media (6.3) | 0.27% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIDocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Analizada | Alta (8.8) | 0.34% | — | Dell Automation Platform | 11/5/2026 | 17/6/2026 | Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress International SMS FOR Contact Form 7 IntegrationAI | 10/5/2026 | 24/7/2026 | WordPress International Sms For Contact Form 7 Integration versión 1.2 contiene una vulnerabilidad de cross-site scripting reflejado en el parámetro page de la interfaz de configuración de administrador. Los atacantes pueden inyectar scripts maliciosos a través del parámetro page en class-sms-log-display.PHP para… | |
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contiene una vulnerabilidad de cross-site scripting reflejado que permite a atacantes no autenticados inyectar scripts maliciosos explotando el parámetro form_id. Los atacantes pueden crear URLs maliciosas hacia code_generator.PHP con cargas útiles de script en el parámetro form_id… | |
| Aplazada | Alta (8.8) | 0.31% | — | Balbooa Joomla Forms BuilderAI | 10/5/2026 | 25/7/2026 | Balbooa Joomla Forms Builder 2.0.6 contiene una vulnerabilidad de inyección SQL no autenticada en el gestor de envío de formularios que permite a atacantes remotos ejecutar consultas SQL arbitrarias. Los atacantes pueden enviar solicitudes POST al componente com_baforms con cargas útiles JSON maliciosas en el… | |
| Aplazada | Media (5.1) | 0.19% | — | Contact Form TO EmailAI | 10/5/2026 | 25/7/2026 | Contact Form to Email 1.3.24 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al crear formularios con etiquetas de script en el campo de nombre del formulario. Los atacantes pueden elaborar nombres de formulario que contienen código… | |
| Aplazada | Alta (7.4) | 0.44% | — | Akamai Guardicore Platform AgentAIAkamai Zero Trust ClientAI | 8/5/2026 | 17/6/2026 | Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs()… | |
| Aplazada | Media (5.3) | 0.44% | — | Cradle Ecommerce PlatformAI | 8/5/2026 | 17/6/2026 | Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a URL as a parameter without properly validating it. As a result, it is possible to… | |
| Analizada | Alta (7.5) | 0.43% | — | Yeti-platform Yeti | 8/5/2026 | 17/6/2026 | yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET). | |
| Analizada | Alta (7.3) | 3.9% | 💥 Exploit | Yeti-platform Yeti | 8/5/2026 | 17/6/2026 | A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server. | |
| Aplazada | Crítica (9.6) | 0.40% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. |