Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
9651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.1) | 0.12% | — | ABB Control Builder AAIABB 800xa FOR Advant MasterAI | 23/6/2026 | 6/10/2026 | Vulnerabilidad de elemento de ruta de búsqueda no controlado en ABB Control Builder A, ABB 800xA para Advant Master. Este problema afecta a Control Builder A: hasta 1.4/4; 800xA para Advant Master: hasta 6.0.3-1, hasta 6.1.1-1, 6.1.1-3, 6.2.0-1. | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Wyse Management Suite | 22/6/2026 | 26/6/2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (4.4) | 0.15% | — | Dell Wyse Management Suite | 22/6/2026 | 26/6/2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Wyse Management Suite | 22/6/2026 | 26/6/2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.8) | 0.44% | — | Dell Wyse Management Suite | 22/6/2026 | 26/6/2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Media (5.9) | 0.40% | — | LiquidfilesAI | 20/6/2026 | 22/6/2026 | Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group. | |
| Aplazada | Crítica (9.3) | 0.80% | — | Brainstormforce Ultimate Addons FOR Beaver BuilderAI | 20/6/2026 | 29/9/2026 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contiene una vulnerabilidad de omisión de autenticación que permite a los atacantes obtener acceso no autorizado explotando la funcionalidad del formulario de inicio de sesión de redes sociales. Los atacantes pueden enviar una solicitud POST al endpoint… | |
| Analizada | Crítica (10) | 89% | ⚠ Explotación activa💥 Exploit | Ollyo SP Page Builder | 20/6/2026 | 7/10/2026 | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | |
| Analizada | Alta (7.1) | 0.40% | — | Cmsjunkie J-cruiseportal | 19/6/2026 | 19/8/2026 | Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to… | |
| Analizada | Alta (8.8) | 0.49% | — | Webkul Ajax Quiz | 19/6/2026 | 19/8/2026 | Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomplace Quiz Deluxe | 19/6/2026 | 19/8/2026 | Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Flexerasoftware Flexnet Manager SuiteAI | 19/6/2026 | 22/6/2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control. | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | Flexerasoftware Flexnet Manager SuiteAI | 19/6/2026 | 22/6/2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level. | |
| Pendiente de análisis | Media (5.6) | 0.25% | — | Cloudflare QuicheAI | 19/6/2026 | 22/6/2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be… | |
| Analizada | Alta (7.7) | 0.52% | — | Openwebui Open Webui | 18/6/2026 | 24/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segment before forwarding it to an admin-configured terminal server. An… | |
| Aplazada | Media (6.9) | 0.52% | — | Hermes WebuiAI | 18/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources,… | |
| Aplazada | Media (5.9) | 0.24% | — | Bricksable FOR Bricks BuilderAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83. | |
| Aplazada | Media (4.3) | 0.25% | — | Pressprimer QuizAI | 18/6/2026 | 18/6/2026 | The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.66% | — | LiquidjsAI | 17/6/2026 | 22/6/2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many <script, <style, or <!--… | |
| Aplazada | Alta (7.5) | 0.66% | — | LiquidjsAI | 17/6/2026 | 22/6/2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers like %9999999d and forwards the captured width unchecked into pad()/padStart(), leading to memory and render limit bypass. In… | |
| Aplazada | Media (5.3) | 0.44% | — | LiquidjsAI | 17/6/2026 | 22/6/2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% render %} tag but does not propagate the parent context's resolved ownPropertyOnly value, resulting in a silent bypass. The new context re-derives… | |
| Aplazada | Media (6.5) | 0.57% | — | LiquidjsAI | 17/6/2026 | 22/6/2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by a {% for %} (or {% tablerow %}) tag whose body is empty. The renderLimit option is documented in docs/source/tutorials/dos.md as the mechanism that… | |
| Aplazada | Media (6.1) | 0.36% | — | LiquidjsAI | 17/6/2026 | 22/6/2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the strip_html filter logic. The strip_html filter is intended to remove HTML tags from a string before rendering, and is widely used as an XSS sanitizer. The… | |
| Analizada | Alta (7.5) | 0.27% | — | Devolutions Unigetui | 17/6/2026 | 24/6/2026 | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a… | |
| Aplazada | Alta (7.1) | 0.47% | — | Hermes WebuiAI | 17/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session data, enabling… |