Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2685▼ 177 respecto a la semana anterior
Críticas / altas1223▼ 305 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

8610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.95%—Wpeverest Everest FormsAI20/4/202617/6/2026
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into…
AplazadaAlta (8.1)3.5%💥 ExploitDrag AND Drop Multiple File Upload FOR Contact Form 7AI17/4/202617/6/2026
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension…
Pendiente de análisisMedia (5.3)0.41%—Redhat Ansible Automation PlatformAI17/4/202617/6/2026
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as…
AplazadaMedia (4.9)0.51%—10web Form MakerAI17/4/202617/6/2026
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input…
Pendiente de análisisAlta (7.1)0.14%—AMD Platform Configuration BlobAI16/4/202615/7/2026
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
Pendiente de análisisMedia (5.1)0.18%—Dell Client Platform BiosAI16/4/202617/6/2026
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
AplazadaCrítica (9.1)0.42%—Sourcecodester Payroll Management AND Information SystemAI16/4/202617/6/2026
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.
AplazadaMedia (4.7)0.27%—Sourcecodester Payroll Management AND Information SystemAI16/4/202617/6/2026
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.
AplazadaMedia (5.3)0.31%—Fluentforms Fluent FormsAI16/4/202617/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user…
AnalizadaMedia (4.8)0.19%—Pega Platform15/4/202617/6/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (5.1)0.19%—Pega Platform15/4/202617/6/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
AnalizadaMedia (5.5)0.15%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux15/4/20261/9/2026
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read…
AnalizadaAlta (7.1)3.1%—SplunkSplunk Cloud Platform15/4/202617/6/2026
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code…
AnalizadaMedia (4.3)0.15%—SplunkSplunk Cloud Platform15/4/202617/6/2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on the app, and does…
AnalizadaMedia (6.6)0.25%—SplunkSplunk Cloud Platform15/4/202617/6/2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username…
AplazadaAlta (8.1)0.14%—Wpforms-liteAI15/4/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
AplazadaMedia (5.3)0.39%—Eshot Form BuilderAI15/4/202617/6/2026
The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). The function is…
AplazadaMedia (5.3)0.27%—Metform PROAI15/4/202617/6/2026
The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form price. This makes it…
AplazadaMedia (4.3)0.23%—Inquiry Form TO Posts OR PagesAI15/4/202617/6/2026
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied fields and missing…
AnalizadaAlta (7.8)0.40%⚠ Explotación activa💥 PoCMicrosoft Defender Antimalware Platform14/4/202624/7/2026
Granularidad insuficiente de control de acceso en Microsoft Defender permite a un atacante autorizado elevar privilegios localmente.
AplazadaAlta (7.2)0.40%—10web Form MakerAI14/4/202617/6/2026
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output…
Pendiente de análisisBaja (2)0.24%—SAP Landscape TransformationAI14/4/202617/6/2026
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a…
Pendiente de análisisMedia (4.2)0.17%—SAP Business Objects Business Intelligence PlatformAI14/4/202617/6/2026
Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after…
AplazadaMedia (6.8)0.27%—10web Form MakerAI13/4/20267/10/2026
El plugin de WordPress Form Maker de 10Web anterior a la versión 1.15.38 no prepara adecuadamente las consultas SQL cuando la función 'MySQL Mapping' está en uso, lo que podría hacer posibles los ataques de inyección SQL en ciertos contextos.
AnalizadaMedia (6.3)0.23%—Fptsoftware Nightwolf Penetration Testing Platform13/4/20267/7/2026
Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser