Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
8594 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (10) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 25/9/2026 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is… | |
| Pendiente de análisis | Alta (8.1) | 1.2% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 22/9/2026 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the… | |
| Pendiente de análisis | Alta (7.1) | 1.5% | — | Adobe Experience Manager Forms JEEAI | 22/9/2026 | 24/9/2026 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of… | |
| Aplazada | Alta (7.2) | 0.41% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin. | |
| Aplazada | Alta (8.8) | 0.35% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the… | |
| Aplazada | Alta (7.5) | 0.30% | — | Ninjaforms Ninja FormsAI | 22/9/2026 | 22/9/2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme,… | |
| Pendiente de análisis | Alta (8.8) | 0.65% | — | Redhat Openshift Container PlatformAIKubernetes Cri-oAI | 21/9/2026 | 1/10/2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the… | |
| Aplazada | Media (5.1) | 0.60% | — | 1millionbot AI Chat PlatformAI | 21/9/2026 | 22/9/2026 | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain… | |
| Aplazada | Media (6.6) | 0.36% | — | Incsub ForminatorAI | 20/9/2026 | 21/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who… | |
| Aplazada | Alta (8.5) | 0.47% | — | Wpforms ForminatorAI | 20/9/2026 | 21/9/2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an… | |
| Aplazada | Alta (7.2) | 0.39% | — | Mdmag Quill FormsAI | 19/9/2026 | 21/9/2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.5) | 0.23% | — | Crocoblock JetformbuilderAI | 19/9/2026 | 21/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server… | |
| Aplazada | Crítica (9.1) | 0.73% | 💥 PoC | Incsub ForminatorAI | 19/9/2026 | 21/9/2026 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Crítica (9.8) | 3.9% | 💥 Exploit | Gravityforms Gravity FormsAI | 19/9/2026 | 21/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a… | |
| Pendiente de análisis | Media (4.3) | 0.48% | — | Openedx Open EDX PlatformAI | 18/9/2026 | 24/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved path strings with startswith instead of comparing path components. A course… | |
| Aplazada | Media (6.1) | 0.35% | — | Openedx Open EDX PlatformAI | 18/9/2026 | 24/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py assigns notification content without sanitizing discussion-title values produced… | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | IBM Platform RTMAI | 18/9/2026 | 22/9/2026 | IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI | 18/9/2026 | 22/9/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Aplazada | Media (4.9) | 0.51% | — | Nexforms NEX FormsAI | 18/9/2026 | 19/9/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (6.1) | 0.18% | — | KA Informatics Technologies LTD BAR Association WebsiteAI | 18/9/2026 | 18/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through 18092026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (5.8) | 0.32% | — | Zealousweb Generate PDF Using Contact Form 7AI | 18/9/2026 | 18/9/2026 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on submitted form content, allowing unauthenticated users to make the server request internal resources and read the response back through the generated PDF. | |
| Aplazada | Media (5.3) | 0.30% | — | Whitestudio Easy Form BuilderAI | 18/9/2026 | 18/9/2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration. | |
| Aplazada | Alta (8.8) | 0.51% | — | Whitestudio Easy Form BuilderAI | 18/9/2026 | 18/9/2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS. | |
| Aplazada | Crítica (9.8) | 1.1% | 💥 PoC | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Analizada | Alta (7.4) | 0.10% | — | Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+71 | 17/9/2026 | 22/9/2026 | Transient DOS while parsing frame during channel usage. |