Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.47% | — | Craftcms Craft CMS | 5/1/2026 | 7/10/2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file` input, specifically its `url` parameter,… | |
| Analizada | Media (4.9) | 0.28% | — | Craftcms Craft CMS | 5/1/2026 | 7/10/2026 | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions… | |
| Modificada | Crítica (9.3) | 0.47% | — | Thedigitalcraft Atomcms | 22/12/2025 | 17/6/2026 | Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks. | |
| Analizada | Crítica (9.9) | 6.6% | 💥 PoC | Craftycontrol Crafty Controller | 17/12/2025 | 17/6/2026 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection. | |
| Analizada | Alta (7.1) | 0.29% | — | Craftycontrol Crafty Controller | 17/12/2025 | 25/9/2026 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification. | |
| Aplazada | Alta (7.1) | 0.31% | — | CraftmycmsAI | 16/10/2025 | 17/6/2026 | A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing attacks or account… | |
| Aplazada | Media (6.6) | 0.35% | — | Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI | 3/10/2025 | 17/6/2026 | Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0. | |
| Aplazada | Media (5.3) | 0.38% | — | Wpcraft WoomsAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpcraft WooMS wooms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooMS: from n/a through <= 9.12. | |
| Aplazada | Media (5.9) | 0.30% | — | Wpcraft WoomsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpcraft WooMS wooms allows Stored XSS.This issue affects WooMS: from n/a through <= 9.12. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Promptcraft Forge StudioAI | 4/9/2025 | 17/6/2026 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` and a few patterns.… | |
| Aplazada | Alta (8.2) | 0.24% | — | Promptcraft Forge StudioAI | 4/9/2025 | 17/6/2026 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists such as r`eplace(/javascript:/gi, '')`. Because the package uses multi-character tokens and each replacement is applied only… | |
| Analizada | Media (6.1) | 0.86% | — | Craftcms Craft CMS | 25/8/2025 | 17/6/2026 | Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and… | |
| Analizada | Media (5.2) | 0.50% | — | Craftcms Craft CMS | 9/8/2025 | 17/6/2026 | Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must meet these requirements: have a… | |
| Aplazada | Crítica (9.3) | 0.14% | — | Plain Craft LauncherAI | 23/7/2025 | 17/6/2026 | PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually… | |
| Analizada | Alta (7.3) | 0.99% | 💥 PoC | Craftercms | 19/6/2025 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue… | |
| Analizada | Media (5.4) | 0.26% | — | Craftycontrol Crafty Controller | 15/6/2025 | 17/6/2026 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. | |
| Aplazada | Baja (3.9) | 0.25% | — | Handcraftedinthealps Goodby CSVAI | 13/6/2025 | 17/6/2026 | handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called "gadget chain"… | |
| Aplazada | Alta (8.1) | 0.76% | — | Bzotheme CraftxtoreAI | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme CraftXtore bw-craftxtore allows PHP Local File Inclusion.This issue affects CraftXtore: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Crafts AND ArtsAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5. | |
| Analizada | Media (6.9) | 1.3% | ⚠ Explotación activa | Craftcms Craft CMS | 7/5/2025 | 17/6/2026 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at… | |
| Analizada | Alta (7.3) | 1.5% | 💥 PoC | Craftcms Craft CMS | 5/5/2025 | 17/6/2026 | Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Craftcms Craft CMS | 25/4/2025 | 24/9/2026 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This… | |
| Aplazada | Alta (7.5) | 0.39% | — | Soundcraft UI SeriesAI | 18/4/2025 | 17/6/2026 | An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpcraft WoomsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpcraft WooMS wooms allows Reflected XSS.This issue affects WooMS: from n/a through <= 9.12. | |
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… |