Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
8641 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Zoho CRM AND Bigin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Insightly | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6. | |
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Freshdesk Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pdf-for-elementor-formsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Object Injection.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Aplazada | Alta (8.8) | 0.43% | — | PDF FOR WpformsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Object Injection.This issue affects PDF for WPForms: from n/a through <= 6.5.0. | |
| Aplazada | Alta (8.8) | 0.43% | — | Add-ons.org PDF FOR Contact Form 7AI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.5.0. | |
| Aplazada | Alta (7.5) | 0.35% | — | Bplugins PDF FOR Gravity FormsAIGravityforms Gravity FormsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Aplazada | Media (6.5) | 0.44% | — | Codepeople Contact Form 7 EmailAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60. | |
| Aplazada | Crítica (9.9) | 0.32% | — | Redefiningtheweb Wordpress Contact Form 7 PDF Google Sheet & DatabaseAI | 18/12/2025 | 5/10/2026 | Vulnerabilidad de carga irrestricta de archivo con tipo peligroso en RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet y Base de Datos rtwwcfp-wordpress-contact-form-7-pdf permite el uso de archivos maliciosos. Este problema afecta a WordPress Contact Form 7 PDF, Google Sheet y Base de Datos: desde n/a hasta… | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+41 | 18/12/2025 | 17/6/2026 | Memory Corruption when processing IOCTLs for JPEG data without verification. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+95 | 18/12/2025 | 17/6/2026 | Memory corruption while loading an invalid firmware in boot loader. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+107 | 18/12/2025 | 17/6/2026 | Memory corruption while handling IOCTL calls to set mode. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+111 | 18/12/2025 | 17/6/2026 | Memory corruption while copying packets received from unix clients. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+209 | 18/12/2025 | 17/6/2026 | Memory corruption while processing MFC channel configuration during music playback. | |
| Analizada | Media (6.7) | 0.09% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+114 | 18/12/2025 | 17/6/2026 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+107 | 18/12/2025 | 17/6/2026 | Memory corruption during video playback when video session open fails with time out error. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+174 | 18/12/2025 | 30/9/2026 | Corrupción de memoria al enrutar paquetes GPR entre usuario y root al manejar un paquete de datos grande. | |
| Analizada | Baja (2.8) | 0.16% | — | Entrinsik Informer | 17/12/2025 | 17/6/2026 | There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses. | |
| Aplazada | Media (6.3) | 0.21% | — | Proliz Software LTD OBS Student Affairs Information SystemAI | 17/12/2025 | 28/9/2026 | Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web (XSS o 'cross-site scripting') vulnerabilidad en Proliz Software Ltd. OBS (Sistema de Información de Asuntos Estudiantiles)0 permite XSS Reflejado. Este problema afecta a OBS (Sistema de Información de Asuntos Estudiantiles)0: antes de… | |
| Analizada | Alta (7.5) | 0.44% | — | Ninjaforms Ninja Forms | 17/12/2025 | 28/9/2026 | El plugin Ninja Forms - The Contact Form Builder That Grows With You para WordPress es vulnerable a la Referencia Directa Insegura a Objetos en versiones hasta la 3.13.2, inclusive. Esto se debe a que el plugin no verifica correctamente que un usuario está autorizado antes de que los endpoints REST 'ninja-forms-views'… | |
| Aplazada | Media (6.1) | 0.26% | — | HtmlformsAI | 17/12/2025 | 17/6/2026 | The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for… | |
| Aplazada | Crítica (9.9) | 0.32% | — | Openedx Open EDX PlatformAI | 16/12/2025 | 17/6/2026 | The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and CourseLimitedStaffRole users are able to list courses they… | |
| Analizada | Alta (8.3) | 0.33% | — | Parseplatform Parse-server | 16/12/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and possibly… | |
| Analizada | Alta (8.1) | 13% | — | Systeminformation | 16/12/2025 | 30/9/2026 | systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell… | |
| Aplazada | Baja (2.1) | 0.23% | — | Xiongwei Smart Catering Cloud PlatformAI | 16/12/2025 | 17/6/2026 | A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now public and may be… |