Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
8610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.31% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state… | |
| Aplazada | Alta (7.2) | 0.30% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the… | |
| Aplazada | Alta (7.2) | 0.33% | — | Rocketgenius Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the… | |
| Aplazada | Alta (7.2) | 0.32% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater… | |
| Aplazada | Alta (7.2) | 0.30% | — | Gravityforms Gravity FormsAI | 2/5/2026 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Passmark BurnintestAIPassmark OsforensicsAIPassmark PerformancetestAI | 1/5/2026 | 17/6/2026 | An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 allows attackers to access kernel memory and escalate privileges via a crafted IOCTL 0x8011E044 call. | |
| Modificada | Alta (7.4) | 0.89% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 8/10/2026 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate… | |
| Modificada | Baja (3.7) | 0.85% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 28/9/2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly… | |
| Modificada | Crítica (9.1) | 0.89% | — | GnutlsRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/4/2026 | 8/10/2026 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service. | |
| Aplazada | Media (5.5) | 0.59% | — | Florensiawidjaja BioinformcpAI | 29/4/2026 | 17/6/2026 | A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of the component Upload Endpoint. This manipulation of the argument Name causes path traversal. The attack can be… | |
| Aplazada | Alta (7.3) | 0.30% | — | Brainstormforce Sureforms PROAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0. | |
| Analizada | Media (4.3) | 0.30% | — | Redhat Openshift Container Platform | 28/4/2026 | 17/6/2026 | A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulnerability allows for… | |
| Aplazada | Media (5.3) | 0.43% | — | Codepeople Booking Calendar Contact FormAI | 24/4/2026 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 1.1% | 💥 PoC | Drag AND Drop File Upload FOR Contact Form 7AI | 24/4/2026 | 17/6/2026 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than… | |
| Analizada | Alta (7.5) | 0.94% | — | Xmlsoft Libxml2Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container Platform+3 | 23/4/2026 | 31/8/2026 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the… | |
| Analizada | Crítica (9.3) | 1.0% | — | Kvcache-ai Ktransformers | 23/4/2026 | 14/7/2026 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted… | |
| Aplazada | Crítica (9.9) | 0.52% | 💥 PoC | Funnelforms LLC FunnelformsproAI | 23/4/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1. | |
| Modificada | Alta (7.8) | 0.20% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the… | |
| Modificada | Media (5) | 0.14% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming… | |
| Analizada | Media (5.5) | 0.15% | — | GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The… | |
| Analizada | Media (5.5) | 0.15% | — | GNU NanoRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/4/2026 | 1/9/2026 | A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Life Sciences Inform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm.… | |
| Analizada | Media (6.3) | 0.24% | — | Oracle Life Sciences Inform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager… |