Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

21.079 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.1)0.32%—Nuxref AppriseAI10/7/202610/7/2026
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by…
AplazadaMedia (4.3)0.46%—Easyappointments Easy AppointmentsAI10/7/202610/7/2026
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to…
AplazadaMedia (6.6)0.87%—HappyformsAI10/7/202629/9/2026
El plugin Happyforms - Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms para WordPress es vulnerable a inclusión local de ficheros en todas las versiones hasta la 1.26.12, inclusive, a través de la función happyforms_get_form_partial(). Esto hace posible que atacantes…
AplazadaCrítica (9.8)1.1%💥 PoCInstant AppointmentAI10/7/202614/7/2026
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AplazadaAlta (7.5)0.30%—Payrange Android APPAI9/7/20269/7/2026
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
AplazadaAlta (7.1)1.1%—Bitapps BIT FormAI9/7/20269/7/2026
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated…
AplazadaCrítica (9.3)0.39%—Oceanicsoft ValeappAI9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AnalizadaMedia (4.9)0.39%—Snipeitapp Snipe-it8/7/202610/7/2026
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API…
AnalizadaCrítica (10)0.64%—Appium/storage-plugin8/7/202626/8/2026
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path…
AnalizadaMedia (6.1)0.56%💥 ExploitAppium/base-driver8/7/202615/7/2026
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError…
AnalizadaBaja (1.3)0.28%—Snipeitapp Snipe-it8/7/202610/7/2026
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the…
AplazadaAlta (7.5)0.49%—APP ACKAI8/7/20268/7/2026
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper…
AplazadaAlta (7.5)0.61%—APP ACKAI8/7/20268/7/2026
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive integer, and ack sized the…
AplazadaAlta (7.5)0.49%—APP ACKAI8/7/20268/7/2026
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does not include --files-from, so a project…
AplazadaAlta (8.1)0.65%—Appointment Booking Calendar Plugin AND Scheduling PluginAI8/7/20268/7/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to…
AplazadaMedia (4.3)0.34%—Actual APP Sync ServerAI7/7/20268/7/2026
Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated…
AplazadaMedia (4.6)0.19%—Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI7/7/20268/7/2026
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard…
AplazadaCrítica (9.3)0.63%—Prog MIS ERP APPAI6/7/20266/7/2026
La aplicación ERP desarrollada por PROG MIS presenta una vulnerabilidad relacionada con el uso de credenciales codificadas de forma fija, lo que permite a atacantes remotos no autenticados iniciar sesión para ver el código de la aplicación y obtener la cuenta y la contraseña de la base de datos.
AplazadaMedia (5.5)2.1%💥 PoCFacebook Create-react-appAIFacebook React-dev-utilsAI6/7/20266/7/2026
Se ha detectado una vulnerabilidad en react create-react-app hasta la versión 5.0.1 en macOS. Esta afecta a la función startBrowserProcess del archivo openBrowser.js del componente react-dev-utils. La manipulación de esta función da lugar a una inyección de comandos del sistema operativo. Es posible explotar el ataque…
AplazadaBaja (2)0.35%—Craterapp CraterAI6/7/20266/7/2026
A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched…
AplazadaMedia (5.3)0.56%—Motopress Appointment BookingAI3/7/20266/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing…
AplazadaMedia (6)0.16%💥 PoCAsus Router APPAI3/7/202617/9/2026
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for…
AnalizadaAlta (7.5)0.36%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
AnalizadaAlta (8.1)0.39%—UI Unifi Talk Application2/7/20269/7/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
AnalizadaAlta (8.3)0.37%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.