Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
39.978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.74% | — | Woocommerce Designer PROAI | 6/10/2026 | 6/10/2026 | Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Woocommerce AppointmentsAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | |
| Aplazada | Crítica (9.3) | 0.37% | — | SchmoozeAI | 6/10/2026 | 6/10/2026 | This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.… | |
| Aplazada | Crítica (9.3) | 0.35% | — | — | 6/10/2026 | 6/10/2026 | An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. | |
| Aplazada | Crítica (10) | 2.1% | — | Totolink X6000rAI | 6/10/2026 | 6/10/2026 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints | |
| Aplazada | Crítica (9.6) | 0.28% | — | TwentyAI | 5/10/2026 | 5/10/2026 | Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field… | |
| Pendiente de análisis | Crítica (9.3) | 0.24% | — | Opensis ClassicAI | 5/10/2026 | 6/10/2026 | openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password. | |
| Pendiente de análisis | Crítica (9.3) | 1.8% | 💥 Exploit | Atlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+4 | 5/10/2026 | 7/10/2026 | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web… | |
| Pendiente de análisis | Crítica (9.2) | 0.69% | — | CamundaAI | 5/10/2026 | 6/10/2026 | Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An… | |
| En análisis | Crítica (9.9) | 0.59% | — | LangflowAI | 5/10/2026 | 6/10/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with… | |
| En análisis | Crítica (9.9) | 0.40% | — | LangflowAILangflow-baseAILangflow LFXAI | 5/10/2026 | 6/10/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server… | |
| Aplazada | Crítica (9.9) | 0.37% | — | Kaleidos PenpotAI | 5/10/2026 | 6/10/2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Stellarwp Advanced Post ManagerAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5. | |
| Aplazada | Crítica (9.8) | 0.28% | — | FineadminAI | 5/10/2026 | 6/10/2026 | FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | |
| Aplazada | Crítica (9.8) | 0.46% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only… | |
| Aplazada | Crítica (9.1) | 0.38% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's… | |
| Aplazada | Crítica (9.8) | 0.39% | — | PlaneAI | 5/10/2026 | 6/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each… | |
| Aplazada | Crítica (9.1) | 0.38% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email… | |
| Aplazada | Crítica (9.6) | 0.32% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another… | |
| Aplazada | Crítica (9.9) | 0.35% | — | PlaneAI | 5/10/2026 | 5/10/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original… | |
| Pendiente de análisis | Crítica (9.8) | 0.86% | — | Apache StrutsAI | 5/10/2026 | 6/10/2026 | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Crítica (9.8) | 0.39% | — | GouguoaAI | 5/10/2026 | 6/10/2026 | GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | |
| Aplazada | Crítica (9.8) | 0.39% | — | WookteamAI | 5/10/2026 | 6/10/2026 | WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An… |