Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.39% | — | Booking ActivitiesAI | 30/9/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Pendiente de análisis | Alta (7.1) | 0.42% | — | ActivitiAI | 14/9/2026 | 24/9/2026 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields,… | |
| Aplazada | Crítica (9.8) | 0.88% | — | AntflowAIActivitiAI | 26/8/2026 | 3/9/2026 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | |
| Aplazada | Alta (8.8) | 0.46% | — | Booking ActivitiesAI | 13/8/2026 | 14/8/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Booking ActivitiesAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions. | |
| Aplazada | Media (6.4) | 0.35% | — | Mirceatm NMR Strava ActivitiesAI | 8/5/2026 | 17/6/2026 | The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Baja (2.1) | 0.41% | — | Alfresco ActivitiAI | 12/3/2026 | 17/6/2026 | A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This… | |
| Aplazada | Alta (8.1) | 0.39% | — | Booking ActivitiesAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44. | |
| Aplazada | Media (4.3) | 0.25% | — | Xola Bookings FOR Tours ActivitiesAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in xola Xola xola-bookings-for-tours-activities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xola: from n/a through <= 1.6. | |
| Modificada | Media (5.4) | 0.26% | — | Mirceatm NMR Strava Activities | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mirceatm NMR Strava activities nmr-strava-activities allows DOM-Based XSS.This issue affects NMR Strava activities: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.1) | 0.38% | — | Booking ActivitiesAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Activities Team Booking Activities allows Reflected XSS.This issue affects Booking Activities: from n/a through 1.15.19. | |
| Modificada | Media (5.4) | 0.27% | — | Neumann Student Activities | 19/10/2014 | 17/6/2026 | The Neumann Student Activities (aka com.appmakr.app153856) application 216607 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.5% | — | Cookpad Android ActivitiesCookpad Android Mykitchen | 2/3/2012 | 16/6/2026 | The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. |