Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.4) | 0.27% | — | KeycloakAI | 16/9/2026 | 17/9/2026 | A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An… | |
| Aplazada | Baja (3.8) | 0.26% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and… | |
| Aplazada | Baja (3.8) | 0.26% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators. | |
| Aplazada | Media (5.3) | 0.30% | — | KboardAI | 16/9/2026 | 17/9/2026 | The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers. | |
| Aplazada | Media (4.3) | 0.29% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID. | |
| Aplazada | Media (5.1) | 0.31% | — | QloappAI | 15/9/2026 | 16/9/2026 | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard. | |
| Aplazada | Crítica (9.5) | 0.51% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. | |
| Aplazada | Alta (7.1) | 0.31% | — | Jhb.software Payload Cloudinary PluginAIPayload CMSAI | 15/9/2026 | 30/9/2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled… | |
| Aplazada | Media (6.5) | 0.44% | — | PyloadAI | 15/9/2026 | 16/9/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated getEvents API endpoint, but get_events does not invoke the available… | |
| Aplazada | Media (4.9) | 0.29% | — | PyloadAI | 15/9/2026 | 16/9/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv4 destinations embedded in 6to4 or NAT64 IPv6 addresses. A low-privileged user can submit an IPv6… | |
| Aplazada | Alta (7.1) | 0.38% | — | JHB Software Payload ALT Text PluginAIPayload CMSAI | 15/9/2026 | 30/9/2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and… | |
| Aplazada | Alta (7.5) | 0.63% | — | Palletsprojects FlaskAIJugmac00 Flask-reuploadedAI | 14/9/2026 | 30/9/2026 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept… | |
| Aplazada | Baja (2.1) | 0.47% | — | Itsourcecode Loan Management SystemAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.54% | — | Soarkey StudentmanagementAI | 14/9/2026 | 14/9/2026 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management.… | |
| Aplazada | Alta (7.1) | 0.30% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store,… | |
| Aplazada | Alta (8.6) | 0.82% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation,… | |
| Aplazada | Media (5.1) | 0.24% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application… | |
| Aplazada | Baja (2) | 2.3% | — | BOAAIDlink Dwr-m921AI | 14/9/2026 | 16/9/2026 | A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.5) | 0.15% | — | Tonec Internet Download ManagerAI | 13/9/2026 | 15/9/2026 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for… | |
| Aplazada | Crítica (9.8) | 0.67% | — | WP Images Upload ON PiclectAI | 12/9/2026 | 14/9/2026 | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server. | |
| Aplazada | Media (5.1) | 0.30% | — | Qlomodules QloappAI | 12/9/2026 | 23/9/2026 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's… | |
| Pendiente de análisis | Media (4.9) | 0.41% | — | KeycloakAI | 11/9/2026 | 16/9/2026 | A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service… | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | CookiesAIKoajs KOAAI | 10/9/2026 | 10/9/2026 | cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | KeycloakAI | 10/9/2026 | 10/9/2026 | A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can… |