Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1775 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.27%—Mattermost Server15/5/202617/6/2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID:…
AplazadaAlta (7.3)0.40%—Flash-attentionAI11/5/202617/6/2026
The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration files to execute…
AplazadaAlta (7.3)0.37%—Flash-attentionAI11/5/202617/6/2026
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use torch.load() without…
AplazadaAlta (8.7)0.62%—Textpattern CMSAI10/5/202625/7/2026
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content area and execute commands by accessing the…
AplazadaMedia (5.1)0.20%—Automattic JetpackAI10/5/20266/10/2026
WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary…
AnalizadaAlta (8)0.34%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+337/5/202617/6/2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
Pendiente de análisisCrítica (9.2)0.77%—Snapone Wattbox 800AISnapone Wattbox 820AI28/4/202624/7/2026
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or…
AnalizadaMedia (6.5)0.35%—Textpattern21/4/202617/6/2026
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in…
AplazadaMedia (6.5)0.41%—CMS FUR Motorrad WerkstattenAI21/4/202617/6/2026
The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaCrítica (9.8)0.80%💥 PoCCodeastro Simple Attendance Management SystemAI17/4/202617/6/2026
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
AnalizadaMedia (6.5)0.22%—Mattermost Server15/4/202617/6/2026
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests..…
AnalizadaAlta (8.1)0.18%—Mattermost Server15/4/202617/6/2026
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID:…
AnalizadaBaja (2.7)0.27%—Mattermost Server15/4/202617/6/2026
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory…
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
AplazadaAlta (8.1)0.53%—PerfmattersAI10/4/202617/6/2026
The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` handlers without any authorization check or nonce verification. The…
AnalizadaMedia (6.5)0.31%—Mattermost9/4/202617/6/2026
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
AnalizadaMedia (6.5)0.31%—Mattermost Server9/4/202617/6/2026
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610
AplazadaMedia (5.3)0.29%—Dfactory Download AttachmentsAI8/4/202624/7/2026
Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.4.0.
AnalizadaAlta (7.5)0.44%—Automattic Activitypub8/4/202624/7/2026
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
AplazadaMedia (5.4)0.29%—Sukimalab Attendance ManagerAI8/4/202624/7/2026
The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all versions up to, and including, 0.6.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaCrítica (9.8)0.42%—Mattiebee DYE6/4/202624/7/2026
dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.