Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
21.035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.30% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. | |
| Analizada | Media (5.3) | 0.16% | — | IBM Websphere Application Server | 18/9/2026 | 24/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. | |
| Pendiente de análisis | Media (4.3) | 0.18% | — | IBM Websphere Application ServerAI | 18/9/2026 | 19/9/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | |
| En análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 30/9/2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. | |
| Pendiente de análisis | Crítica (10) | 0.57% | — | IBM MQ ApplianceAI | 18/9/2026 | 21/9/2026 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication. | |
| Aplazada | Media (5.4) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 18/9/2026 | 18/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| En análisis | Media (6.3) | 0.21% | — | Hclsoftware Appscan 360AI | 18/9/2026 | 18/9/2026 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification… | |
| Aplazada | Alta (8.8) | 0.31% | — | Techin2b ApplicationAI | 18/9/2026 | 18/9/2026 | Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Baja (2.7) | 0.32% | — | Bookit Booking Appointment CalendarAI | 18/9/2026 | 18/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment… | |
| Aplazada | Media (5.3) | 0.30% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on… | |
| Aplazada | Media (4.8) | 0.27% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that… | |
| Aplazada | Media (6.5) | 0.38% | — | Apple PhotosAI | 18/9/2026 | 18/9/2026 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine… | |
| Aplazada | Media (4.3) | 0.33% | — | Approval APPAI | 18/9/2026 | 18/9/2026 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Xerial Snappy-javaAI | 17/9/2026 | 22/9/2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. | |
| Pendiente de análisis | Media (6.9) | 0.50% | — | Xerial Snappy-javaAI | 17/9/2026 | 22/9/2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write… | |
| Analizada | Crítica (9.1) | 0.44% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.60% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Frappe Learning Management SystemAI | 17/9/2026 | 23/9/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Openreception Appointment Booking SoftwareAI | 17/9/2026 | 30/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind… | |
| Aplazada | Alta (7.1) | 0.48% | — | Frappe HRAI | 17/9/2026 | 30/9/2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py,… | |
| Aplazada | Crítica (9) | 0.70% | — | AnyqueryAIGoogle ChromeAIBraveAIMicrosoft EdgeAI+1 | 17/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript or… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | AppwriteAI | 17/9/2026 | 22/9/2026 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd… | |
| Pendiente de análisis | Baja (2.6) | 0.22% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID:… | |
| Pendiente de análisis | Baja (3.7) | 0.13% | — | Mattermost Desktop APPAI | 17/9/2026 | 18/9/2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Apple ContainerizationAI | 16/9/2026 | 18/9/2026 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0. |