Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
21.069 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. | |
| Analizada | Alta (7.5) | 0.40% | — | IBM APP Connect Enterprise | 30/7/2026 | 5/8/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Websphere Application Server | 30/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |
| Aplazada | Media (5.3) | 0.34% | — | Appointment Booking PluginAI | 30/7/2026 | 30/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval… | |
| Aplazada | Baja (3.7) | 0.25% | — | Bitapps BIT FormAI | 30/7/2026 | 30/7/2026 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished. | |
| Aplazada | Media (4.3) | 0.29% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer… | |
| Aplazada | Media (4.3) | 0.27% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. | |
| Aplazada | Baja (3.8) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | |
| Aplazada | Baja (3.8) | 0.26% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and… | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Aplazada | Media (6.5) | 0.30% | — | Dynamiapps Frontend AdminAI | 30/7/2026 | 30/7/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms. | |
| Analizada | Alta (8.8) | 0.15% | — | IBM Websphere Application Server | 29/7/2026 | 4/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Crítica (9.8) | 0.53% | — | IBM Websphere Application Server | 29/7/2026 | 4/8/2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. | |
| Aplazada | Media (6.5) | 0.48% | — | Appcheap APP BuilderAI | 29/7/2026 | 30/7/2026 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app… | |
| Aplazada | Alta (7.1) | 0.37% | — | FrappeAIFrappe ErpnextAI | 29/7/2026 | 30/7/2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as… | |
| Aplazada | Media (5.4) | 0.23% | — | Easyappointments Easy AppointmentsAI | 29/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an… | |
| Aplazada | Media (6.9) | 0.38% | — | Igloohome Smart Lock Mobile APPAI | 28/7/2026 | 30/7/2026 | In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls. | |
| Modificada | Alta (8.7) | 0.34% | — | IBM Websphere Application Server | 28/7/2026 | 6/8/2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests. | |
| Analizada | Alta (7.5) | 0.50% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Websphere Application Server | 28/7/2026 | 5/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. |