Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | 0.32% | — | Nuxref AppriseAI | 10/7/2026 | 10/7/2026 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by… | |
| Aplazada | Media (4.3) | 0.46% | — | Easyappointments Easy AppointmentsAI | 10/7/2026 | 10/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Aplazada | Media (6.6) | 0.87% | — | HappyformsAI | 10/7/2026 | 29/9/2026 | El plugin Happyforms - Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms para WordPress es vulnerable a inclusión local de ficheros en todas las versiones hasta la 1.26.12, inclusive, a través de la función happyforms_get_form_partial(). Esto hace posible que atacantes… | |
| Aplazada | Crítica (9.8) | 1.1% | 💥 PoC | Instant AppointmentAI | 10/7/2026 | 14/7/2026 | The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Alta (7.5) | 0.30% | — | Payrange Android APPAI | 9/7/2026 | 9/7/2026 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends. | |
| Aplazada | Alta (7.1) | 1.1% | — | Bitapps BIT FormAI | 9/7/2026 | 9/7/2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Oceanicsoft ValeappAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Media (4.9) | 0.39% | — | Snipeitapp Snipe-it | 8/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API… | |
| Analizada | Crítica (10) | 0.64% | — | Appium/storage-plugin | 8/7/2026 | 26/8/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path… | |
| Analizada | Media (6.1) | 0.56% | 💥 Exploit | Appium/base-driver | 8/7/2026 | 15/7/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError… | |
| Analizada | Baja (1.3) | 0.28% | — | Snipeitapp Snipe-it | 8/7/2026 | 10/7/2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the… | |
| Aplazada | Alta (7.5) | 0.49% | — | APP ACKAI | 8/7/2026 | 8/7/2026 | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper… | |
| Aplazada | Alta (7.5) | 0.61% | — | APP ACKAI | 8/7/2026 | 8/7/2026 | App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive integer, and ack sized the… | |
| Aplazada | Alta (7.5) | 0.49% | — | APP ACKAI | 8/7/2026 | 8/7/2026 | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does not include --files-from, so a project… | |
| Aplazada | Alta (8.1) | 0.65% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 8/7/2026 | 8/7/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to… | |
| Aplazada | Media (4.3) | 0.34% | — | Actual APP Sync ServerAI | 7/7/2026 | 8/7/2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated… | |
| Aplazada | Media (4.6) | 0.19% | — | Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI | 7/7/2026 | 8/7/2026 | Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard… | |
| Aplazada | Crítica (9.3) | 0.63% | — | Prog MIS ERP APPAI | 6/7/2026 | 6/7/2026 | La aplicación ERP desarrollada por PROG MIS presenta una vulnerabilidad relacionada con el uso de credenciales codificadas de forma fija, lo que permite a atacantes remotos no autenticados iniciar sesión para ver el código de la aplicación y obtener la cuenta y la contraseña de la base de datos. | |
| Aplazada | Media (5.5) | 2.1% | 💥 PoC | Facebook Create-react-appAIFacebook React-dev-utilsAI | 6/7/2026 | 6/7/2026 | Se ha detectado una vulnerabilidad en react create-react-app hasta la versión 5.0.1 en macOS. Esta afecta a la función startBrowserProcess del archivo openBrowser.js del componente react-dev-utils. La manipulación de esta función da lugar a una inyección de comandos del sistema operativo. Es posible explotar el ataque… | |
| Aplazada | Baja (2) | 0.35% | — | Craterapp CraterAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched… | |
| Aplazada | Media (5.3) | 0.56% | — | Motopress Appointment BookingAI | 3/7/2026 | 6/7/2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing… | |
| Aplazada | Media (6) | 0.16% | 💥 PoC | Asus Router APPAI | 3/7/2026 | 17/9/2026 | An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for… | |
| Analizada | Alta (7.5) | 0.36% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed. | |
| Analizada | Alta (8.1) | 0.39% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | |
| Analizada | Alta (8.3) | 0.37% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. |