Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.39%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is…
AplazadaCrítica (9.8)0.84%—Dancer2 Plugin Auth ExtensibleAI15/8/202626/8/2026
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from…
AplazadaAlta (8.7)0.74%—Getgrav Grav API PluginAI14/8/202631/8/2026
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. The scope cap is applied only inside requirePermission(), while the scheduler and backups gates use a bare isSuperAdmin() check that never consults…
AplazadaAlta (8.7)0.47%—Getgrav Grav-plugin-apiAI14/8/202631/8/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that reads access.api.super directly without…
AplazadaAlta (8.6)0.49%—Getgrav Grav-plugin-apiAI14/8/202631/8/2026
Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a scope-aware permission check, so a least-privilege API key (scoped to api.users.write) minted on a…
AplazadaAlta (8.7)0.47%—Getgrav Grav-plugin-apiAI14/8/20268/9/2026
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's scopes are read directly from the request…
AplazadaAlta (7.2)0.35%—Getgrav Grav-plugin-apiAI14/8/20268/9/2026
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of requireSuper(). Because isSuperAdmin() reads…
AplazadaAlta (8.7)0.73%—Getgrav Grav-plugin-apiAI14/8/202631/8/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege API key scoped only to api.pages.write and minted on a super account…
AplazadaMedia (5.3)0.33%—Getgrav Grav-plugin-apiAI14/8/202631/8/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in requirePermission()) is skipped. As a result,…
AplazadaAlta (8.7)0.56%—Getgrav Grav-plugin-apiAI14/8/202631/8/2026
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes…
AplazadaAlta (8.7)0.47%—Getgrav Grav-plugin-apiAI14/8/202630/9/2026
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController, AccountsConfigController,…
Pendiente de análisisAlta (8.7)1.00%—Opensearch SQL PluginAIApache SparkAI13/8/202614/8/2026
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
Pendiente de análisisMedia (4.7)0.28%—Backstage Plugin-auth-backendAILinuxfoundation BackstageAI13/8/202618/9/2026
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for…
AplazadaBaja (3.7)0.14%—Estatik Real Estate PluginAI12/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is…
AplazadaMedia (5.3)0.16%—Fullworksplugins Quick Paypal PaymentsAI12/8/202626/8/2026
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.
Pendiente de análisisAlta (7.1)0.21%—Zoom VDI ClientAIZoom VDI PluginsAI11/8/202628/8/2026
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
AplazadaMedia (5)0.27%—Plugins360 All-in-one Video GalleryAI10/8/202626/8/2026
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
Pendiente de análisisAlta (7.1)0.58%—Gstreamer Gst-plugins-uglyAI10/8/202616/9/2026
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads.…
Pendiente de análisisAlta (7.6)0.38%—Gstreamer Gst-plugins-badAI10/8/202618/9/2026
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to…
AplazadaMedia (6.5)0.41%💥 PoCWeplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
AplazadaAlta (8.8)0.53%—Weplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
AplazadaAlta (7.5)0.23%—Estatik Real Estate PluginAI7/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the…
AplazadaMedia (5.3)0.16%—Fivestarplugins Five Star Restaurant ReservationsAI6/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending…
AplazadaMedia (5.3)0.16%—Simple-membership-plugin Simple MembershipAI6/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they…
AplazadaAlta (7.5)0.40%—Paymentplugins Payment Plugins FOR PaypalAI6/8/202626/8/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
Orbitaley — Vulnerabilidades