Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
8594 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.16% | — | Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Calculated Fields FormAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Aplazada | Alta (8.5) | 0.22% | — | Mollie FormsAI | 23/9/2026 | 23/9/2026 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Aplazada | Alta (7.7) | 0.24% | — | Craftcms FormieAI | 23/9/2026 | 30/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks.… | |
| Aplazada | Alta (8.2) | 0.31% | — | Craftcms FormieAI | 23/9/2026 | 30/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete submission without session binding, ownership validation, or a valid… | |
| Aplazada | Alta (8.5) | 0.29% | — | Verbb FormieAI | 23/9/2026 | 30/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An… | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Media (5.3) | 0.43% | — | Solspace FreeformAICraftcms Craft CMSAI | 23/9/2026 | 23/9/2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in submitted field values,… | |
| Aplazada | Media (6.5) | 0.21% | — | Global IT Informatics Technology Services INC WeollAI | 23/9/2026 | 23/9/2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44. | |
| Aplazada | Media (5.3) | 0.19% | — | Incsub ForminatorAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post… | |
| Aplazada | Media (5.3) | 0.12% | — | Wpmudev ForminatorAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Advanced Contact Form 7 DBAI | 23/9/2026 | 23/9/2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.8) | 0.24% | — | Subscribe FormsAI | 23/9/2026 | 23/9/2026 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the… | |
| Aplazada | Baja (3.7) | 0.15% | — | Wpmudev Forminator FormsAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail… | |
| Aplazada | Baja (3.1) | 0.13% | — | Incsub ForminatorAI | 23/9/2026 | 23/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user,… | |
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Baja (2.1) | 0.19% | — | Tduckcloud Tduck-platformAI | 22/9/2026 | 25/9/2026 | A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument… | |
| Pendiente de análisis | Crítica (9.6) | 0.73% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope… | |
| Pendiente de análisis | Alta (8.7) | 0.81% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction.… | |
| Pendiente de análisis | Crítica (9.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 23/9/2026 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… |