Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.15% | — | Forge12 Interactive Gmbh F12-profilerAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9. | |
| Aplazada | Alta (7.1) | 0.17% | — | Manuelvicedo Forge Front-end Page BuilderAI | 3/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder forge allows Stored XSS.This issue affects Forge – Front-End Page Builder: from n/a through <= 1.4.6. | |
| Analizada | Media (5.1) | 0.23% | — | Forgerock Access Management | 29/10/2024 | 17/6/2026 | An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks | |
| Modificada | Alta (7.5) | 0.41% | — | Bricksforge | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | |
| Modificada | Alta (7.5) | 0.39% | — | Bricksforge | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | |
| Aplazada | Media (5.3) | 0.40% | — | Forge12 Interactive Gmbh Captcha Honeypot FOR Contact Form 7AI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.11.3. | |
| Aplazada | Media (5.3) | 0.36% | — | BricksforgeAI | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | |
| Modificada | Crítica (9.8) | 0.78% | — | Forgerock Access Management | 27/3/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2. | |
| Modificada | Media (6.5) | 1.9% | — | FontforgeDebian LinuxFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. | |
| Modificada | Media (4.2) | 1.1% | — | FontforgeDebian LinuxFedoraproject Fedora | 26/2/2024 | 17/6/2026 | Splinefont in FontForge through 20230101 allows command injection via crafted filenames. | |
| Modificada | Media (5.3) | 0.80% | — | Forgejo | 3/12/2023 | 17/6/2026 | Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL. | |
| Modificada | Alta (7.5) | 0.61% | — | Forgejo | 3/12/2023 | 17/6/2026 | Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication. | |
| Modificada | Crítica (9.1) | 0.86% | — | Forgejo | 3/12/2023 | 17/6/2026 | In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions. | |
| Modificada | Alta (8.8) | 0.34% | — | Designsandcode Forget About Shortcode Buttons | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+7 | 27/7/2023 | 17/6/2026 | When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | |
| Modificada | Media (6.1) | 0.38% | — | Radioforge Radio Forge Muses Player With Skins | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions. | |
| Modificada | Media (5.5) | 0.22% | — | Forget IT Project Forget IT | 17/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up to 1.3. This affects an unknown part of the file js/settings.js. The manipulation of the argument setForgetTime with the input 0 leads to infinite loop. It is possible to launch the attack on the local host. Upgrading to… | |
| Modificada | Crítica (9.8) | 0.91% | — | Forgerock Access Management | 14/4/2023 | 17/6/2026 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0. | |
| Modificada | Media (5.4) | 0.36% | — | Oxidforge Oxid Eshop | 11/4/2023 | 17/6/2026 | OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent. | |
| Modificada | Alta (7.5) | 0.35% | — | Forgerock Ldap Connector | 29/3/2023 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13. | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock Java Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1 | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock WEB Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1 | |
| Modificada | Alta (8.8) | 0.72% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php. | |
| Modificada | Crítica (9.8) | 0.74% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php. | |
| Modificada | Alta (7.5) | 0.53% | — | Forged Alliance Forever Project Forged Alliance Forever | 6/1/2023 | 17/6/2026 | A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named… |