Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

9672 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.41%—Dpgaspar Flask-appbuilder11/9/202517/6/2026
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and accessible, despite not being displayed in the user interface. This allows an…
AnalizadaCrítica (9.8)0.76%—Ruisitech Ruisibi8/9/202517/6/2026
rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
AplazadaMedia (6.4)0.24%—Smart Table BuilderAI6/9/202517/6/2026
The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaAlta (7.1)0.19%—Beaver Builder Wordpress AssistantAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2.
AplazadaMedia (4.3)0.13%—Fullworksplugins Quick Paypal PaymentsAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= 5.7.46.
AplazadaMedia (6.5)0.17%—Luis Rock Master Paper Collapse ToggleAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luis Rock Master Paper Collapse Toggle master-paper-collapse-toggle allows Stored XSS.This issue affects Master Paper Collapse Toggle: from n/a through <= 1.1.
AplazadaAlta (7.1)0.12%—Quick-event-calendarAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Event Calendar: from n/a through <= 1.4.9.
AnalizadaMedia (5.5)0.09%—Huawei EmuiHuawei Harmonyos5/9/202517/6/2026
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.
AplazadaAlta (8.5)0.16%—Tkeasygui TkeasyuiAI5/9/202517/6/2026
Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.
AplazadaCrítica (9.3)2.7%—Tkeasygui TkeasyuiAI5/9/202517/6/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from…
AnalizadaCrítica (9.4)0.53%—Ruijie Rg-es228gs-p FirmwareRuijie Rg-es209gc-p FirmwareRuijie Rg-es205gc-p FirmwareRuijie Rg-es205gc Firmware+163/9/202517/6/2026
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
AnalizadaBaja (2)0.46%—Campcodes Online Recruitment Management System3/9/202517/6/2026
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of the file /admin/index.php. The manipulation of the argument page results in file inclusion. It is possible to launch the attack remotely. The exploit has been released to the public and may be…
ModificadaMedia (4.3)0.28%—Jenkins Global Build Stats3/9/202517/6/2026
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
AnalizadaBaja (2)0.29%—Carmelo Fruit Shop Management System3/9/202517/6/2026
A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such manipulation of the argument product_code/gen_name/product_name/supplier leads to cross site scripting. It is possible to launch the attack…
AplazadaMedia (6.9)0.07%—Learningcircuit Local Deep ResearchAI3/9/202517/6/2026
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given…
AnalizadaCrítica (9.8)0.38%—Ruisitech Ruisibi2/9/202517/6/2026
rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
Se encontró una vulnerabilidad en Undertow donde solicitudes de cliente malformadas pueden desencadenar restablecimientos de flujo del lado del servidor sin activar contadores de abuso. Este problema, conocido como el ataque “MadeYouReset”, permite a clientes maliciosos inducir una carga de trabajo excesiva del…
AnalizadaAlta (8.1)0.24%—Dieboldnixdorf Vynamic Security Suite29/8/202517/6/2026
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile…
AnalizadaAlta (8.1)0.37%—Dieboldnixdorf Vynamic Security Suite29/8/202517/6/2026
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions,…
AplazadaBaja (3.4)0.43%—UispAI29/8/202517/6/2026
An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.
AplazadaAlta (7.5)0.62%—Opinionstage Poll Survey Quiz MakerAI28/8/202517/6/2026
Control inadecuado del nombre de fichero para la declaración Include/Require en un programa PHP (vulnerabilidad de 'PHP inclusión remota de ficheros') en el plugin Poll, Survey &amp; Quiz Maker de Assaf Parag de Opinion Stage permite la inclusión local de ficheros PHP. Este problema afecta al plugin Poll, Survey &amp;…
AplazadaAlta (7.1)0.23%—Koen Schuit Nextgen Gallery SearchAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Koen Schuit NextGEN Gallery Search nextgen-gallery-search-galleries allows Reflected XSS.This issue affects NextGEN Gallery Search: from n/a through <= 2.12.
AnalizadaMedia (5.1)0.25%—Opensolution Quick.cms28/8/202517/6/2026
QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with…
AnalizadaMedia (5.3)0.19%—Opensolution Quick.cms28/8/202517/6/2026
QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the…
AnalizadaMedia (5.3)0.19%—Opensolution Quick.cms28/8/202517/6/2026
QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website.…