Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

8594 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (10)1.2%—Adobe Experience Manager Forms JEEAI22/9/202625/9/2026
Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is…
Pendiente de análisisAlta (8.1)1.2%—Adobe Experience Manager Forms JEEAI22/9/202622/9/2026
Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…
Pendiente de análisisAlta (7.1)1.5%—Adobe Experience Manager Forms JEEAI22/9/202624/9/2026
Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of…
AplazadaAlta (7.2)0.41%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.
AplazadaAlta (8.8)0.35%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the…
AplazadaAlta (7.5)0.30%—Ninjaforms Ninja FormsAI22/9/202622/9/2026
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,…
Pendiente de análisisAlta (8.8)0.65%—Redhat Openshift Container PlatformAIKubernetes Cri-oAI21/9/20261/10/2026
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the…
AplazadaMedia (5.1)0.60%—1millionbot AI Chat PlatformAI21/9/202622/9/2026
Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain…
AplazadaMedia (6.6)0.36%—Incsub ForminatorAI20/9/202621/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who…
AplazadaAlta (8.5)0.47%—Wpforms ForminatorAI20/9/202621/9/2026
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an…
AplazadaAlta (7.2)0.39%—Mdmag Quill FormsAI19/9/202621/9/2026
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.5)0.23%—Crocoblock JetformbuilderAI19/9/202621/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server…
AplazadaCrítica (9.1)0.73%💥 PoCIncsub ForminatorAI19/9/202621/9/2026
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AplazadaCrítica (9.8)3.9%💥 ExploitGravityforms Gravity FormsAI19/9/202621/9/2026
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a…
Pendiente de análisisMedia (4.3)0.48%—Openedx Open EDX PlatformAI18/9/202624/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved path strings with startswith instead of comparing path components. A course…
AplazadaMedia (6.1)0.35%—Openedx Open EDX PlatformAI18/9/202624/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced…
Pendiente de análisisAlta (8.6)0.30%—IBM Platform RTMAI18/9/202622/9/2026
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Pendiente de análisisMedia (6.1)0.20%—IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI18/9/202622/9/2026
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…
AplazadaMedia (4.9)0.51%—Nexforms NEX FormsAI18/9/202619/9/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaMedia (6.1)0.18%—KA Informatics Technologies LTD BAR Association WebsiteAI18/9/202618/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through 18092026. NOTE: The vendor was contacted early about this disclosure but did not…
AplazadaMedia (5.8)0.32%—Zealousweb Generate PDF Using Contact Form 7AI18/9/202618/9/2026
The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF.
AplazadaMedia (5.3)0.30%—Whitestudio Easy Form BuilderAI18/9/202618/9/2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.
AplazadaAlta (8.8)0.51%—Whitestudio Easy Form BuilderAI18/9/202618/9/2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
AplazadaCrítica (9.8)1.1%💥 PoCMulti Uploader FOR Gravity FormsAI17/9/202619/9/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload…
AnalizadaAlta (7.4)0.10%—Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+7117/9/202622/9/2026
Transient DOS while parsing frame during channel usage.
Orbitaley — Vulnerabilidades