Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.075 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 14/7/2026 | 15/7/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Aplazada | Crítica (9.1) | 0.70% | — | Ueberauth AppleAI | 14/7/2026 | 15/7/2026 | Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not validate any registered claims. The iss, aud,… | |
| Aplazada | Alta (7.1) | 0.32% | — | EasyappointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers,… | |
| Aplazada | Baja (3.1) | 0.21% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the… | |
| Aplazada | Baja (2.7) | 0.31% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 15/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches… | |
| Aplazada | Baja (3.3) | 0.23% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 29/7/2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update`… | |
| Aplazada | Baja (2.6) | 0.24% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public… | |
| Aplazada | Media (6.9) | 0.56% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 29/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`)… | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 14/7/2026 | Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation… | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | SAP Netweaver Application Server JavaAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the… | |
| Pendiente de análisis | Crítica (9.9) | 0.56% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 29/7/2026 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the… | |
| Analizada | Alta (8.1) | 0.47% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to… | |
| Analizada | Crítica (9.1) | 0.68% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on… | |
| Aplazada | Alta (8.7) | 0.78% | — | Luci-app-banipAI | 13/7/2026 | 15/7/2026 | luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the… | |
| Analizada | Alta (8.2) | 0.40% | — | Appium-mcp | 13/7/2026 | 26/8/2026 | MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-desc, resource-id, and locator selector values — directly into an… | |
| Aplazada | Media (6.5) | 0.33% | — | Nsquared Simply Schedule AppointmentsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4. | |
| Aplazada | Alta (8.5) | 0.36% | — | Appsbd ViteposAIAppsbd Vitepos-liteAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Nsquared Simply Schedule AppointmentsAI | 13/7/2026 | 9/10/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through 1.6.11.11. | |
| Aplazada | Alta (8.7) | 0.36% | — | Luci-app-upnpAIMiniupnpdAI | 12/7/2026 | 30/9/2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,… | |
| Aplazada | Alta (8.7) | 0.88% | — | Openwrt Luci-app-samba4AISambaAI | 12/7/2026 | 30/9/2026 | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command… | |
| Aplazada | Media (6.9) | 0.59% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0. | |
| Aplazada | Alta (8.6) | 0.68% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0. | |
| Aplazada | Alta (7.1) | 0.54% | — | FrappeAI | 10/7/2026 | 13/7/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version 16.19.0. | |
| Aplazada | Media (5.3) | 0.61% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.110.0. | |
| Aplazada | Media (5.3) | 0.38% | — | FrappeAI | 10/7/2026 | 14/7/2026 | Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2. |