Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2772▲ 13 respecto a la semana anterior
Críticas / altas1288▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
9658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.62% | — | Profile Builder PROAI | 2/5/2026 | 17/6/2026 | The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked… | |
| Aplazada | Media (5.3) | 0.51% | — | Appcheap APP BuilderAI | 2/5/2026 | 17/6/2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 5.6.0. This is due to missing authorization validation in the `upload_avatar()` function, which accepts an attacker-controlled `user_id` parameter… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nextlevelbuilder Ui-ux-pro-max-skillAI | 1/5/2026 | 17/6/2026 | A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from… | |
| Aplazada | Baja (2.1) | 0.41% | — | Nextlevelbuilder Ui-ux-pro-max-skillAI | 1/5/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to… | |
| Aplazada | Media (5.5) | 0.51% | — | Nextlevelbuilder GoclawAINextlevelbuilder Goclaw LiteAI | 30/4/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this… | |
| Modificada | Media (5.4) | 0.32% | — | Redhat Build OF Keycloak | 30/4/2026 | 26/6/2026 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly… | |
| Aplazada | Media (5.5) | 0.59% | — | Ezequiroga Mcp-basesAI | 29/4/2026 | 17/6/2026 | A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c. This impacts the function search_papers of the file research_server.py. Performing a manipulation of the argument topic results in path traversal. Remote exploitation of the attack is… | |
| Aplazada | Media (5.5) | 0.61% | — | Douinc Mkdocs-mcp-pluginAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a manipulation of the argument docs_dir/file_path results in path traversal. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Aplazada | Media (5.5) | 0.47% | — | Bidingcc BuildingaiAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. It is possible to… | |
| Analizada | Alta (8.8) | 0.34% | — | Espressif Arduino-esp32 | 24/4/2026 | 17/6/2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruption issue in the NBNS packet handling path. When NetBIOS is enabled by calling NBNS.begin(...), the device listens on UDP port 137 and… | |
| Analizada | Alta (8.1) | 0.38% | — | Uuidjs Uuid | 24/4/2026 | 17/6/2026 | uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0. | |
| Aplazada | Media (5.3) | 0.32% | — | Maxiblocks BuilderAI | 24/4/2026 | 17/6/2026 | The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with Author-level access and… | |
| Analizada | Baja (2.5) | 0.13% | — | Uuidjs Uuid | 23/4/2026 | 8/7/2026 | uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue. | |
| Aplazada | Media (5.5) | 0.43% | 💥 PoC | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the use of the `file://`… | |
| Aplazada | Alta (7.3) | 0.36% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an asset. Version… | |
| Aplazada | Alta (7.3) | 0.36% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functions (`getJSON`, `request`, etc.). An authenticated user with… | |
| Aplazada | Alta (7.2) | 0.40% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is fetched using the "Backup" `HttpClient` without any SSRF… | |
| Aplazada | Media (6.1) | 0.24% | — | Ravster Inquiry CartAI | 22/4/2026 | 17/6/2026 | The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the… | |
| Aplazada | Media (4.4) | 0.30% | — | Private WP SuiteAI | 22/4/2026 | 17/6/2026 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in all versions up to, and including, 0.4.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Analizada | Crítica (9.8) | 0.73% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion. | |
| Analizada | Alta (7.2) | 0.68% | — | Get-hermes Hermes WEB UI | 21/4/2026 | 17/6/2026 | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers… | |
| Aplazada | Media (4.8) | 0.16% | — | Nesquena Hermes-webuiAI | 21/4/2026 | 17/6/2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive… | |
| Aplazada | Media (5.3) | 0.38% | — | Nesquena Hermes-webuiAI | 21/4/2026 | 17/6/2026 | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk by manipulating workspace path parameters in endpoints such as /api/session/new, /api/session/update, /api/chat/start, and… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Business Process Management Suite | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… |