Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2685▼ 177 respecto a la semana anterior
Críticas / altas1223▼ 305 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
8610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.95% | — | Wpeverest Everest FormsAI | 20/4/2026 | 17/6/2026 | The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into… | |
| Aplazada | Alta (8.1) | 3.5% | 💥 Exploit | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 17/4/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Redhat Ansible Automation PlatformAI | 17/4/2026 | 17/6/2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as… | |
| Aplazada | Media (4.9) | 0.51% | — | 10web Form MakerAI | 17/4/2026 | 17/6/2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input… | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | AMD Platform Configuration BlobAI | 16/4/2026 | 15/7/2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | Dell Client Platform BiosAI | 16/4/2026 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |
| Aplazada | Media (4.7) | 0.27% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |
| Aplazada | Media (5.3) | 0.31% | — | Fluentforms Fluent FormsAI | 16/4/2026 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user… | |
| Analizada | Media (4.8) | 0.19% | — | Pega Platform | 15/4/2026 | 17/6/2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (5.1) | 0.19% | — | Pega Platform | 15/4/2026 | 17/6/2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. | |
| Analizada | Media (5.5) | 0.15% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/4/2026 | 1/9/2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in an out-of-bounds read… | |
| Analizada | Alta (7.1) | 3.1% | — | SplunkSplunk Cloud Platform | 15/4/2026 | 17/6/2026 | In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code… | |
| Analizada | Media (4.3) | 0.15% | — | SplunkSplunk Cloud Platform | 15/4/2026 | 17/6/2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on the app, and does… | |
| Analizada | Media (6.6) | 0.25% | — | SplunkSplunk Cloud Platform | 15/4/2026 | 17/6/2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a specially crafted username… | |
| Aplazada | Alta (8.1) | 0.14% | — | Wpforms-liteAI | 15/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2. | |
| Aplazada | Media (5.3) | 0.39% | — | Eshot Form BuilderAI | 15/4/2026 | 17/6/2026 | The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). The function is… | |
| Aplazada | Media (5.3) | 0.27% | — | Metform PROAI | 15/4/2026 | 17/6/2026 | The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form price. This makes it… | |
| Aplazada | Media (4.3) | 0.23% | — | Inquiry Form TO Posts OR PagesAI | 15/4/2026 | 17/6/2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied fields and missing… | |
| Analizada | Alta (7.8) | 0.40% | ⚠ Explotación activa💥 PoC | Microsoft Defender Antimalware Platform | 14/4/2026 | 24/7/2026 | Granularidad insuficiente de control de acceso en Microsoft Defender permite a un atacante autorizado elevar privilegios localmente. | |
| Aplazada | Alta (7.2) | 0.40% | — | 10web Form MakerAI | 14/4/2026 | 17/6/2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output… | |
| Pendiente de análisis | Baja (2) | 0.24% | — | SAP Landscape TransformationAI | 14/4/2026 | 17/6/2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Business Objects Business Intelligence PlatformAI | 14/4/2026 | 17/6/2026 | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after… | |
| Aplazada | Media (6.8) | 0.27% | — | 10web Form MakerAI | 13/4/2026 | 7/10/2026 | El plugin de WordPress Form Maker de 10Web anterior a la versión 1.15.38 no prepara adecuadamente las consultas SQL cuando la función 'MySQL Mapping' está en uso, lo que podría hacer posibles los ataques de inyección SQL en ciertos contextos. | |
| Analizada | Media (6.3) | 0.23% | — | Fptsoftware Nightwolf Penetration Testing Platform | 13/4/2026 | 7/7/2026 | Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser |