Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
930 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.55% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1. | |
| Aplazada | Alta (8.6) | 0.38% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Aplazada | Media (6.9) | 0.22% | — | Phpjabbers PHP JabbersAI | 31/7/2026 | 29/9/2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating… | |
| Aplazada | Alta (8.6) | 0.38% | — | Phpjabbers PHP JabbersAI | 31/7/2026 | 29/9/2026 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in… | |
| Aplazada | Crítica (9.3) | 0.44% | — | Phpjabbers CAR Rental ScriptAI | 31/7/2026 | 29/9/2026 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Aplazada | Media (6.9) | 0.29% | — | ABB MMS ServerAI | 30/7/2026 | 8/9/2026 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte… | |
| Aplazada | Alta (8.7) | 0.51% | — | Ninenines CowlibAINinenines CowboyAIRabbitmqAI | 28/7/2026 | 30/7/2026 | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl… | |
| Aplazada | Media (5.9) | 0.15% | — | ABB KNX Update ToolAIBJE KNX Update ToolAI | 17/7/2026 | 17/7/2026 | Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175. | |
| Analizada | Alta (7.8) | 0.25% | — | Tabby | 15/7/2026 | 30/7/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete CVE-2026-45038 fix for control characters… | |
| Analizada | Media (5.3) | 0.41% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read… | |
| Analizada | Alta (7.5) | 0.55% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker… | |
| Analizada | Alta (8.7) | 2.8% | 💥 Exploit | Broadcom Rabbitmq Server | 10/7/2026 | 29/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and… | |
| Analizada | Media (4.9) | 0.35% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user… | |
| Analizada | Alta (7) | 0.35% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow.… | |
| Analizada | Crítica (10) | 0.50% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is… | |
| Analizada | Alta (7) | 0.38% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route… | |
| Analizada | Alta (7.1) | 0.22% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript… | |
| Modificada | Media (5.7) | 0.25% | — | Broadcom Rabbitmq Server | 10/7/2026 | 14/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser… | |
| Analizada | Alta (7.1) | 0.43% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This… | |
| Analizada | Crítica (10) | 0.63% | — | Broadcom Rabbitmq Server | 10/7/2026 | 13/7/2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound… | |
| Aplazada | Alta (7.1) | 0.25% | — | Handl UTM GrabberAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | ABB Control Builder AAIABB 800xa FOR Advant MasterAI | 23/6/2026 | 6/10/2026 | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1. | |
| Aplazada | Alta (8.3) | 0.29% | — | Softlabbd Integrate Google DriveAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8. | |
| Aplazada | Media (5.6) | 0.12% | — | ABB FreelanceAI | 11/6/2026 | 7/10/2026 | Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024. | |
| Analizada | Alta (7.2) | 0.18% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. |