Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
8641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.36% | — | V-sol Gpon Epon OLT PlatformAI | 24/12/2025 | 17/6/2026 | V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their… | |
| Aplazada | Media (6.5) | 0.29% | — | Codepeople WP Time Slots Booking FormAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.39. | |
| Aplazada | Alta (7.6) | 0.33% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 24/12/2025 | 7/10/2026 | Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') vulnerabilidad en CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot permite Inyección SQL Ciega. Este problema afecta a Integration for Contact Form 7 HubSpot: desde n/a hasta menor o igual a 1.4.2. | |
| Aplazada | Media (5.3) | 0.25% | — | Funnelforms FreeAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad de falta de autorización en Funnelforms Funnelforms Free funnelforms-free permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Funnelforms Free: desde n/a hasta menor o igual que 3.8. | |
| Aplazada | Media (6.5) | 0.26% | — | Jegstudio Gutenverse FormAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad por falta de autorización en Jegstudio Gutenverse Form gutenverse-form permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a Gutenverse Form: desde n/a hasta menor o igual que 2.3.1. | |
| Aplazada | Media (5.9) | 0.21% | — | Ecommerce Platforms Gift HuntAI | 24/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Ecommerce Platforms Gift Hunt gift-hunt permite XSS Almacenado. Este problema afecta a Gift Hunt: desde n/a hasta menor o igual que 2.0.2. | |
| Aplazada | Media (6.8) | 0.37% | 💥 PoC | Gravityforms Gravity FormsAI | 24/12/2025 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A flaw has been found in code-projects Student Information System 1.0. This issue affects some unknown processing of the file /searchresults.php. Executing manipulation of the argument searchbox can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 24/12/2025 | 17/6/2026 | A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of the file /profile.php. Performing manipulation of the argument firstname/lastname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.37% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.34% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.33% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the… | |
| Analizada | Alta (7.8) | 0.36% | — | Huggingface Transformers | 23/12/2025 | 17/6/2026 | Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target… | |
| Aplazada | Media (6.5) | 0.26% | — | Vikasratudi VpsiformAI | 23/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form allows Retrieve Embedded Sensitive Data.This issue affects VPSUForm: from n/a through <= 3.2.24. | |
| Aplazada | Alta (7.2) | 0.37% | 💥 PoC | Brainstormforce SureformsAI | 21/12/2025 | 28/9/2026 | El plugin SureForms para WordPress es vulnerable a cross-site scripting almacenado a través de los parámetros de los campos del formulario en todas las versiones hasta la 2.2.0, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que atacantes no autenticados inyecten… | |
| Aplazada | Alta (8.1) | 0.39% | — | Redirection FOR Contact Form 7AI | 21/12/2025 | 28/9/2026 | El plugin Redirection for Contact Form 7 para WordPress es vulnerable a la carga arbitraria de archivos debido a la falta de validación del tipo de archivo en la función 'move_file_to_upload' en todas las versiones hasta la 3.2.7, inclusive. Esto hace posible que atacantes no autenticados copien archivos arbitrarios… | |
| Analizada | Crítica (9.6) | 0.57% | — | Openagentplatform Dive | 19/12/2025 | 17/6/2026 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 0.11.1 in the Mermaid diagram rendering component. The application allows the execution of arbitrary JavaScript via… | |
| Aplazada | Alta (7.5) | 0.27% | — | Ays-pro Easy FormAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Salesforce | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Hubspot | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Constant Contact Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.2. |