Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

21.069 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.37%—Bitapps BIT FormAI5/8/202626/8/2026
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting.
AplazadaAlta (7.5)0.54%—VikappointmentsAI5/8/202612/8/2026
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value…
AplazadaAlta (7.1)0.43%—Frappe ErpnextAI4/8/202628/8/2026
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.
AplazadaAlta (8.7)0.44%—Line Android APPAI4/8/202628/8/2026
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause…
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft ExcelMicrosoft Office 2019Microsoft Office 2021+14/8/20269/8/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
AplazadaBaja (1.9)0.21%—Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI3/8/202612/8/2026
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with…
AplazadaMedia (6.4)0.16%—Jiransoft Appcheck PROAI3/8/202612/8/2026
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather…
AplazadaBaja (1.9)0.14%—Textplus Text Message AND Call APPAI3/8/202612/8/2026
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly…
AplazadaAlta (8.7)3.3%—Openwrt Luci-app-dockermanAIOpenwrtAI3/8/20269/9/2026
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the…
AplazadaAlta (8.7)0.93%—Openwrt Luci-app-bmx7AI3/8/20269/9/2026
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the…
AplazadaCrítica (9.8)0.51%—Menulux Software INC Mobile APPAI3/8/202626/8/2026
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
AplazadaBaja (0.9)0.11%—Meesho Online Shopping APPAI3/8/202612/8/2026
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The…
AplazadaMedia (6.5)0.34%—Simply Schedule AppointmentsAI3/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,…
AplazadaMedia (5.1)0.24%—Luci-app-adblock-fastAI2/8/20269/9/2026
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.
AplazadaAlta (7.5)0.41%💥 PoCSimply Schedule AppointmentsAI2/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
Pendiente de análisisMedia (6.8)0.41%—Luci-app-https-dns-proxyAI1/8/20268/9/2026
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser…
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (4.8)0.24%—Bitapps BIT FormAI1/8/202629/9/2026
El plugin de WordPress Bit Form anterior a la versión 3.1.4 no sanea una de sus configuraciones de visualización de formularios conversacionales antes de renderizarla en el formulario de cara al público, permitiendo a usuarios con altos privilegios (como administradores, que no poseen la capacidad unfiltered_html en…
AplazadaAlta (8.8)0.45%—Dynamiapps Frontend AdminAI31/7/202626/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output…
Pendiente de análisisMedia (5.5)0.14%—Ansible-collection-redhat-leappAI30/7/20263/8/2026
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive…
Pendiente de análisisMedia (6.2)0.38%—Ansible-collection-redhat-leappAI30/7/20263/8/2026
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed…
AnalizadaAlta (8.5)0.58%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
AnalizadaAlta (7.5)0.56%—IBM Websphere Application Server30/7/202612/8/2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
AnalizadaAlta (7.5)0.53%—IBM Websphere Application Server30/7/20265/8/2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
AnalizadaCrítica (9.8)0.73%—IBM APP Connect Enterprise30/7/20265/8/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.