Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.15%—Forge12 Interactive Gmbh F12-profilerAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9.
AplazadaAlta (7.1)0.17%—Manuelvicedo Forge Front-end Page BuilderAI3/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder forge allows Stored XSS.This issue affects Forge – Front-End Page Builder: from n/a through <= 1.4.6.
AnalizadaMedia (5.1)0.23%—Forgerock Access Management29/10/202417/6/2026
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
ModificadaAlta (7.5)0.41%—Bricksforge9/6/202417/6/2026
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
ModificadaAlta (7.5)0.39%—Bricksforge9/6/202417/6/2026
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
AplazadaMedia (5.3)0.40%—Forge12 Interactive Gmbh Captcha Honeypot FOR Contact Form 7AI4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.11.3.
AplazadaMedia (5.3)0.36%—BricksforgeAI10/4/202417/6/2026
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
ModificadaCrítica (9.8)0.78%—Forgerock Access Management27/3/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
ModificadaMedia (6.5)1.9%—FontforgeDebian LinuxFedoraproject Fedora26/2/202417/6/2026
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
ModificadaMedia (4.2)1.1%—FontforgeDebian LinuxFedoraproject Fedora26/2/202417/6/2026
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
ModificadaMedia (5.3)0.80%—Forgejo3/12/202317/6/2026
Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.
ModificadaAlta (7.5)0.61%—Forgejo3/12/202317/6/2026
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
ModificadaCrítica (9.1)0.86%—Forgejo3/12/202317/6/2026
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
ModificadaAlta (8.8)0.34%—Designsandcode Forget About Shortcode Buttons9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.
ModificadaAlta (7.8)0.18%—ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+727/7/202317/6/2026
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
ModificadaMedia (6.1)0.38%—Radioforge Radio Forge Muses Player With Skins27/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions.
ModificadaMedia (5.5)0.22%—Forget IT Project Forget IT17/4/202317/6/2026
A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up to 1.3. This affects an unknown part of the file js/settings.js. The manipulation of the argument setForgetTime with the input 0 leads to infinite loop. It is possible to launch the attack on the local host. Upgrading to…
ModificadaCrítica (9.8)0.91%—Forgerock Access Management14/4/202317/6/2026
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
ModificadaMedia (5.4)0.36%—Oxidforge Oxid Eshop11/4/202317/6/2026
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.
ModificadaAlta (7.5)0.35%—Forgerock Ldap Connector29/3/202317/6/2026
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13.
ModificadaCrítica (9.8)0.97%—Forgerock Java Policy Agents28/2/202317/6/2026
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
ModificadaCrítica (9.8)0.97%—Forgerock WEB Policy Agents28/2/202317/6/2026
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
ModificadaAlta (8.8)0.72%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.
ModificadaCrítica (9.8)0.74%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.
ModificadaAlta (7.5)0.53%—Forged Alliance Forever Project Forged Alliance Forever6/1/202317/6/2026
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named…