Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

8610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaAlta (8.8)0.45%—Divvydrive Information Technologies INC DivvydriveAI7/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
AplazadaAlta (8.3)0.22%—Divvydrive Information Technologies INC DivvydriveAI7/5/20265/10/2026
Modificación indebidamente controlada de atributos de objeto determinados dinámicamente, vulnerabilidad de asignación de recursos sin límites ni limitación en DivvyDrive Information Technologies Inc. DivvyDrive permite la asignación excesiva, inundación. Este problema afecta a DivvyDrive: desde 4.8.2.19 antes de…
ModificadaCrítica (9.8)0.94%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux7/5/20268/10/2026
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability…
AplazadaMedia (6.5)0.45%—Incsub ForminatorAI7/5/202617/6/2026
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check before saving the scheduled export configuration, unlike the…
AplazadaMedia (5.3)0.42%—Incsub ForminatorAI7/5/202617/6/2026
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including…
AplazadaMedia (4.9)0.83%—Fluentforms Fluent FormsAI6/5/202617/6/2026
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the…
Pendiente de análisisMedia (5)0.28%—Runzero PlatformAI5/5/202617/6/2026
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N (5.0, Medium). This issue was fixed in…
AplazadaAlta (7.5)0.46%💥 PoC10web Form MakerAI5/5/202617/6/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaAlta (7.5)0.65%—Wpmudev ForminatorAI5/5/202617/6/2026
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path]' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the…
AplazadaMedia (5.3)0.35%—Incsub ForminatorAI5/5/202617/6/2026
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied Stripe PaymentIntent identifiers in the public payment flow. This…
AplazadaAlta (8.7)0.60%—Conditional Fields FOR Contact Form 7AI4/5/202617/6/2026
Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or…
AnalizadaAlta (7.8)0.07%—Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+1724/5/202629/6/2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
AnalizadaAlta (7)0.05%—Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+964/5/20267/10/2026
Corrupción de memoria durante la creación de un proceso en el procesador de señal digital debido a un fallo de asignación a nivel de kernel.
AnalizadaMedia (5.5)0.07%—Qualcomm X2000086 FirmwareQualcomm X2000090 FirmwareQualcomm X2000092 FirmwareQualcomm X2000094 Firmware+274/5/20267/10/2026
Revelación de información durante el procesamiento de callbacks del gestor de IOCTL sin verificar el tamaño del búfer.
AplazadaMedia (5.3)0.39%—ILM Informatique JopenddocumentAI4/5/202617/6/2026
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.
AplazadaMedia (4.8)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
AplazadaBaja (2.4)0.14%—ILM Informatique OpenconcertoAI4/5/202617/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects OpenConcerto: 1.7.5.
Pendiente de análisisAlta (8.3)0.57%—Redhat Ansible Automation PlatformAI4/5/202626/8/2026
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or…
AplazadaAlta (7.2)1.7%—Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI4/5/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.
AplazadaMedia (5.5)3.2%—Tiandy Easy7 Integrated Management PlatformAI3/5/202617/6/2026
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo/updateDbBackupInfo. Such manipulation of the argument week leads to os command injection. The attack can be executed remotely. The exploit…
AplazadaBaja (2.1)0.38%—Acrel Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit…
AplazadaMedia (5.5)0.41%—Acrel Electrical Eems Enterprise Power Operation AND Maintenance Cloud PlatformAI3/5/202617/6/2026
A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The…
AplazadaAlta (7.2)0.32%—NEX FormsAI3/5/202617/6/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.3)0.42%💥 PoCHuggingface TransformersAILmsys SglangAI2/5/202617/6/2026
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boolean results in…