Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9651 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)0.45%—Hermes WebuiAI30/6/202614/7/2026
Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object without setting its profile in the /api/session/import handler, so the imported session is persisted with a null profile. Because a null profile is treated as the default profile…
ModificadaMedia (6.5)0.49%—Redhat Build OF Keycloak30/6/20265/8/2026
A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege…
ModificadaMedia (4.3)0.39%—Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack30/6/20265/8/2026
A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific…
AnalizadaMedia (6.5)0.40%—Redhat Build OF Keycloak30/6/20261/7/2026
A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns…
AplazadaCrítica (9.3)0.63%—Advantech Hospital Queuing ManagementAI30/6/202630/6/2026
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
AplazadaAlta (8.7)0.55%—Advantech Hospital Queuing ManagementAI30/6/202630/6/2026
Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
AplazadaCrítica (9.8)0.55%—Dbix QuickormAISQL AbstractAI30/6/202630/6/2026
DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys,…
AplazadaMedia (6.5)0.24%—Squidex CMSAI29/6/202630/6/2026
Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
AplazadaAlta (7.1)0.25%—Pluginops Landing Page BuilderAI29/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
AnalizadaCrítica (10)31%⚠ Explotación activa💥 ExploitJoomlack Page Builder CK29/6/20267/10/2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AplazadaBaja (1.3)0.36%—Aidc-ai Comfyui-copilotAI28/6/202629/6/2026
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed…
AplazadaMedia (4.3)0.47%—Quizandsurveymaster Quiz AND Survey MasterAI27/6/202629/6/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.42%—Siteorigin Page BuilderAI27/6/202629/6/2026
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (4.3)0.26%—Harmonicdesign HD QuizAI27/6/202629/6/2026
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and…
AplazadaMedia (4.3)0.29%—Bopo Woocommerce Product Bundle BuilderAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
AplazadaMedia (5.4)0.29%—Liquidweb WpcompleteAI26/6/202626/6/2026
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
AplazadaAlta (7.1)0.25%—Quick Interest SliderAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
AplazadaAlta (8.8)0.42%—Fusion BuilderAI26/6/202629/6/2026
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
AplazadaAlta (7.5)0.42%—Johnson & Johnson Campus RecruitingAI26/6/202626/6/2026
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
ModificadaMedia (6.5)0.52%—Redhat Build OF Apicurio Registry26/6/202625/8/2026
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs…
ModificadaAlta (7.4)0.34%—Redhat Build OF Apicurio Registry25/6/202626/8/2026
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the…
ModificadaAlta (8.5)0.44%—Redhat Build OF Apicurio Registry25/6/202626/8/2026
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload…
AnalizadaAlta (8.1)0.30%—Redhat Build OF Keycloak25/6/202615/7/2026
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any…
ModificadaAlta (8.1)0.65%—Redhat Build OF Keycloak25/6/202614/9/2026
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query…
AnalizadaMedia (4.6)0.29%—Redhat Build OF Keycloak25/6/20261/7/2026
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of…