Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.45% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS or… | |
| Aplazada | Alta (8.1) | 0.41% | — | Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete… | |
| Aplazada | Alta (8.8) | 0.64% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with… | |
| Aplazada | Media (4.6) | 0.29% | — | Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API plugin POST /api/v1/media pipeline in HandlesMediaUploads::processUploadedFile() validates an SVG filename extension but does not invoke Security::sanitizeSVG(). An attacker with… | |
| Aplazada | Alta (7.5) | 0.35% | — | Outranking PluginAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | |
| Aplazada | Alta (8.6) | 0.36% | — | Stigmem-nodeAIStigmem-plugin-multi-tenantAI | 19/8/2026 | 24/9/2026 | stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id… | |
| Aplazada | Media (5.4) | 0.29% | — | Weplugins WP MapsAI | 19/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | |
| Aplazada | Alta (7.5) | 0.44% | — | Pickplugins User VerificationAI | 19/8/2026 | 26/8/2026 | The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them,… | |
| Aplazada | Media (5.5) | 0.17% | — | Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI | 18/8/2026 | 9/9/2026 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second… | |
| Aplazada | Media (5.5) | 0.29% | — | Linuxfabrik Monitoring PluginsAI | 18/8/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path… | |
| Aplazada | Alta (7.8) | 0.21% | — | Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI | 18/8/2026 | 9/9/2026 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins… | |
| Aplazada | Alta (7) | 0.18% | — | Linuxfabrik Monitoring PluginsAIDebian Apt-getAI | 18/8/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that… | |
| Aplazada | Media (4.8) | 0.17% | — | Konstanty Bialkowski LibmodplugAI | 18/8/2026 | 8/9/2026 | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array.… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Gingerplugins Sticky Chat WidgetAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpzoom Forms Contact Form Plugin FOR GutenbergAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | |
| Aplazada | Alta (8.7) | 0.47% | — | Getgrav GravAIGetgrav Grav Plugin APIAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST… | |
| Aplazada | Crítica (9.3) | 0.31% | — | Getgrav Grav Plugin APIAI | 18/8/2026 | 8/9/2026 | Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the account's raw super-admin flag and ACL grants. As a result, an… | |
| Aplazada | Alta (8.6) | 0.22% | — | Getgrav Grav-plugin-apiAIGetgrav GravAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes in special… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Getgrav GravAIGetgrav Grav-plugin-apiAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the account's raw super-admin ACL flag (access.api.super) instead of… | |
| Aplazada | Alta (7.1) | 0.39% | — | Getgrav Grav Plugin APIAI | 18/8/2026 | 8/9/2026 | grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suffix' parameter (via POST /api/v1/pages/batch) unvalidated. An authenticated user… | |
| Aplazada | Alta (8.6) | 0.41% | — | Getgrav Grav-plugin-apiAI | 18/8/2026 | 8/9/2026 | grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav Form PluginAI | 18/8/2026 | 8/9/2026 | Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav Plugin-apiAI | 18/8/2026 | 8/9/2026 | Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with api.media.write permission can upload files containing executable script payloads… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | MattermostAIMattermost Gitlab PluginAI | 17/8/2026 | 18/8/2026 | Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to… | |
| Aplazada | Alta (7.2) | 0.58% | — | Booking-wp-plugin BooklyAI | 16/8/2026 | 20/8/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… |