Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
21.613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.31% | — | VK ALL IN ONE Expansion UnitAI | 18/9/2026 | 18/9/2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.24% | — | Ninjateam FilebirdAI | 18/9/2026 | 19/9/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.27% | — | Infinitewp ClientAI | 18/9/2026 | 18/9/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on… | |
| Aplazada | Media (6.5) | 0.27% | — | Magnigenie RestropressAI | 18/9/2026 | 18/9/2026 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order. | |
| Aplazada | Crítica (9.1) | 0.82% | — | AF CompanionAI | 18/9/2026 | 18/9/2026 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution. | |
| Analizada | Alta (7.8) | 0.23% | ⚠ Explotación activa | Acronis Backup | 17/9/2026 | 18/9/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. | |
| Analizada | Alta (7.5) | 0.54% | — | Microsoft Azure Machine Learning | 17/9/2026 | 25/9/2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Frappe Learning Management SystemAI | 17/9/2026 | 23/9/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its… | |
| Analizada | Media (5.5) | 0.20% | — | Openimageio | 17/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application linked to OpenImageIO can reach BMP palette handling in… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Matrimonial SystemAI | 17/9/2026 | 17/9/2026 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public… | |
| Pendiente de análisis | Media (5.3) | 0.45% | — | OmniblocksAI | 17/9/2026 | 23/9/2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was… | |
| Aplazada | Alta (7.6) | 0.14% | — | KubernetesAITalosAIEtcdAISiderolabs OmniAI | 17/9/2026 | 24/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an… | |
| Pendiente de análisis | Baja (2.7) | 0.49% | — | TalosAISiderolabs OmniAI | 17/9/2026 | 23/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator… | |
| Aplazada | Alta (7) | 0.14% | — | Siderolabs OmniAI | 17/9/2026 | 24/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can… | |
| Aplazada | Alta (8.4) | 0.19% | — | UnigetAI | 17/9/2026 | 30/9/2026 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. The resulting path is passed to the configured… | |
| Aplazada | Baja (1) | 0.15% | — | UnigetAI | 17/9/2026 | 24/9/2026 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. An attacker who can influence the… | |
| Aplazada | Alta (8.2) | 0.28% | — | Joni1802 TS3 ManagerAI | 17/9/2026 | 30/9/2026 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as… | |
| Aplazada | Media (5.8) | 0.10% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot… | |
| Aplazada | Media (6) | 0.54% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file… | |
| Aplazada | Alta (8.3) | 0.54% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing… | |
| Aplazada | Media (6) | 0.55% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply… | |
| Aplazada | Alta (8.3) | 0.22% | — | Midnightbsd MportAI | 17/9/2026 | 17/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror… | |
| Aplazada | Alta (8.6) | 0.14% | — | Measurement Computing Universal Library FOR LinuxAI | 17/9/2026 | 28/9/2026 | There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior versions. | |
| Aplazada | Media (6) | 0.15% | — | Midnightbsd MportAI | 17/9/2026 | 21/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by… | |
| Aplazada | Alta (8.3) | 0.26% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed… |