Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Memberpress Corporate AccountsAI | 12/9/2026 | 14/9/2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like… | |
| Aplazada | Alta (8.2) | 0.31% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the forgotten-password path in… | |
| Aplazada | Alta (7.1) | 0.22% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Managed-serviceaccountAIKubernetes Addon-managerAI | 18/8/2026 | 20/8/2026 | A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation… | |
| Pendiente de análisis | Crítica (9.9) | 0.69% | — | Kuadrant AuthpolicyAIKubernetes ServiceaccountAI | 10/8/2026 | 27/8/2026 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized… | |
| Aplazada | Media (5.4) | 0.28% | — | Block User AccountAI | 10/8/2026 | 26/8/2026 | The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API. | |
| Aplazada | Alta (8.1) | 0.41% | — | Custom Fields Account Registration FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Systemd-homedAIFreedesktop AccountsserviceAI | 24/7/2026 | 24/7/2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Account | 24/7/2026 | 30/7/2026 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (4.3) | 0.36% | — | Bizimhesap Information Systems Industry AND Trade INC Online Pre-accounting SoftwareAI | 23/7/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | |
| Aplazada | Media (4.4) | 0.34% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 16/7/2026 | 17/7/2026 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Customize MY Account FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions. | |
| Aplazada | Alta (7.2) | 0.47% | — | FrontaccountingAI | 29/6/2026 | 1/7/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attackers with SA_GLANALYTIC permission can inject arbitrary SQL by supplying a closing parenthesis… | |
| Aplazada | Alta (7.2) | 0.47% | — | FrontaccountingAI | 29/6/2026 | 29/6/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malicious code into the PARAM_2 and PARAM_3 POST parameters. Attackers can exploit time-based blind SQL… | |
| Aplazada | Alta (7.1) | 0.23% | — | FrontaccountingAI | 29/6/2026 | 29/6/2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized… | |
| Aplazada | Alta (8.7) | 0.98% | — | FrontaccountingAI | 29/6/2026 | 30/6/2026 | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files… | |
| Aplazada | Media (5.3) | 0.49% | — | Devs AccountingAI | 24/6/2026 | 25/6/2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This is due to the get_single_account() REST API callback being registered with a permission_callback that unconditionally returns true, providing no… | |
| Aplazada | Media (5.3) | 0.39% | — | Devs AccountingAI | 24/6/2026 | 25/6/2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on the delete_single_account() function in versions up to, and including, 1.2.0. The REST route… | |
| Analizada | Alta (8.8) | 0.49% | — | Wdmtech Vaccount | 19/6/2026 | 21/8/2026 | Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads in the vid… | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Media (6.1) | 0.21% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.19% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width,… |