Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.4)0.45%—Getgrav Grav API PluginAI19/8/20269/9/2026
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS or…
AplazadaAlta (8.1)0.41%—Grav API PluginAI19/8/20269/9/2026
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete…
AplazadaAlta (8.8)0.64%—Getgrav Grav API PluginAI19/8/20269/9/2026
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with…
AplazadaMedia (4.6)0.29%—Grav API PluginAI19/8/20269/9/2026
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API plugin POST /api/v1/media pipeline in HandlesMediaUploads::processUploadedFile() validates an SVG filename extension but does not invoke Security::sanitizeSVG(). An attacker with…
AplazadaAlta (7.5)0.35%—Outranking PluginAI19/8/202620/8/2026
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
AplazadaAlta (8.6)0.36%—Stigmem-nodeAIStigmem-plugin-multi-tenantAI19/8/202624/9/2026
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id…
AplazadaMedia (5.4)0.29%—Weplugins WP MapsAI19/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.
AplazadaAlta (7.5)0.44%—Pickplugins User VerificationAI19/8/202626/8/2026
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them,…
AplazadaMedia (5.5)0.17%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second…
AplazadaMedia (5.5)0.29%—Linuxfabrik Monitoring PluginsAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path…
AplazadaAlta (7.8)0.21%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins…
AplazadaAlta (7)0.18%—Linuxfabrik Monitoring PluginsAIDebian Apt-getAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that…
AplazadaMedia (4.8)0.17%—Konstanty Bialkowski LibmodplugAI18/8/20268/9/2026
libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array.…
AplazadaCrítica (9.3)0.40%—Gingerplugins Sticky Chat WidgetAI18/8/202620/8/2026
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
AplazadaMedia (6.5)0.22%—Wpzoom Forms Contact Form Plugin FOR GutenbergAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
AplazadaAlta (8.7)0.47%—Getgrav GravAIGetgrav Grav Plugin APIAI18/8/20268/9/2026
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST…
AplazadaCrítica (9.3)0.31%—Getgrav Grav Plugin APIAI18/8/20268/9/2026
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the account's raw super-admin flag and ACL grants. As a result, an…
AplazadaAlta (8.6)0.22%—Getgrav Grav-plugin-apiAIGetgrav GravAI18/8/20268/9/2026
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes in special…
AplazadaCrítica (9.3)0.30%—Getgrav GravAIGetgrav Grav-plugin-apiAI18/8/20268/9/2026
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the account's raw super-admin ACL flag (access.api.super) instead of…
AplazadaAlta (7.1)0.39%—Getgrav Grav Plugin APIAI18/8/20268/9/2026
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suffix' parameter (via POST /api/v1/pages/batch) unvalidated. An authenticated user…
AplazadaAlta (8.6)0.41%—Getgrav Grav-plugin-apiAI18/8/20268/9/2026
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are…
AplazadaMedia (5.1)0.24%—Getgrav Grav Form PluginAI18/8/20268/9/2026
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw…
AplazadaMedia (5.1)0.26%—Getgrav Plugin-apiAI18/8/20268/9/2026
Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with api.media.write permission can upload files containing executable script payloads…
Pendiente de análisisMedia (4.3)0.29%—MattermostAIMattermost Gitlab PluginAI17/8/202618/8/2026
Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to…
AplazadaAlta (7.2)0.58%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…