Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
8642 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.67% | — | Gravityforms Gravity FormsAI | 18/11/2025 | 17/6/2026 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.3) | 0.57% | — | Lsfusion Platform | 17/11/2025 | 7/10/2026 | Se ha identificado una debilidad en la plataforma lsfusion hasta 6.1. Esta vulnerabilidad afecta a la función unpackFile del archivo server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. Esta manipulación causa salto de ruta. Es posible iniciar el ataque remotamente. | |
| Analizada | Media (5.5) | 0.59% | — | Lsfusion Platform | 17/11/2025 | 7/10/2026 | Se determinó una vulnerabilidad en la plataforma lsfusion hasta la versión 6.1. Afectada por esta vulnerabilidad es la función UploadFileRequestHandler del archivo platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. La manipulación del argumento sid puede conducir a un salto… | |
| Analizada | Media (5.5) | 0.70% | — | Lsfusion Platform | 17/11/2025 | 7/10/2026 | Se encontró una vulnerabilidad en la plataforma lsfusion hasta la versión 6.1. La función DownloadFileRequestHandler del archivo web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java está afectada. La manipulación del argumento Version resulta en un salto de ruta. La explotación remota… | |
| Analizada | Baja (2) | 0.26% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.php. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.36% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 0.35% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Student Information System | 16/11/2025 | 17/6/2026 | A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.3) | 0.26% | — | Crocoblock JetformbuilderAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en jetmonsters JetFormBuilder jetformbuilder permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a JetFormBuilder: desde n/a hasta menor o igual que 3.5.3. | |
| Aplazada | Media (6.5) | 0.23% | — | Codepeople Contact Form TO EmailAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en codepeople Contact Form Email contact-form-to-email permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Contact Form Email: desde n/a hasta menor o igual que 1.3.58. | |
| Aplazada | Media (5.9) | 0.17% | — | Aman Popup Addon FOR Ninja FormsAI | 13/11/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en el complemento Aman Popup para Ninja Forms popup-addon-for-ninja-forms permite XSS Almacenado. Este problema afecta al complemento Popup para Ninja Forms: desde n/a hasta menor o igual que 3.5.1. | |
| Aplazada | Media (5.3) | 0.79% | 💥 Exploit | Brainstormforce SureformsAI | 13/11/2025 | 7/10/2026 | El plugin SureForms para WordPress es vulnerable a la exposición de información sensible en todas las versiones hasta la 1.13.1, inclusive, a través del registro de metadatos de publicación '_srfm_email_notification'. Esto se debe a la configuración del parámetro 'auth_callback' a '__return_true', lo que permite el… | |
| Aplazada | Media (5.3) | 0.32% | — | Bitplatform BoilerplateAIMicrosoft Visual StudioAIMicrosoft NETAI | 13/11/2025 | 7/10/2026 | Bitplatform Boilerplate es una plantilla de proyecto de Visual Studio y .NET. Las versiones anteriores a la 9.11.3 están afectadas por una vulnerabilidad de cross-site scripting (XSS) en WebInteropApp/WebAppInterop, lo que podría permitir a los atacantes inyectar scripts maliciosos que comprometan la seguridad e… | |
| Analizada | Media (6.5) | 0.24% | — | IBM Qradar Security Information AND Event Manager | 12/11/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. | |
| Analizada | Baja (3.5) | 0.28% | — | SplunkSplunk Cloud Platform | 12/11/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a… | |
| Analizada | Media (6.1) | 0.24% | — | SplunkSplunk Cloud Platform | 12/11/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splunk Web login endpoint. When an authenticated user visits the… | |
| Aplazada | Alta (7.3) | 0.25% | — | Divvydrive Information Technologies INC Digital Corporate WarehouseAI | 12/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22. | |
| Analizada | Media (5.5) | 0.20% | — | Adobe Format Plugins | 11/11/2025 | 17/6/2026 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.20% | — | Adobe Format Plugins | 11/11/2025 | 17/6/2026 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.20% | — | Adobe Format Plugins | 11/11/2025 | 17/6/2026 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.20% | — | Adobe Format Plugins | 11/11/2025 | 17/6/2026 | Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.19% | — | Adobe Format Plugins | 11/11/2025 | 17/6/2026 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |