Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
2094 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | — | — | Stellarwp Advanced Post ManagerAI | 5/10/2026 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5. | |
| Aplazada | Media (4.3) | 0.28% | — | Monetizemore Advanced ADSAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26. | |
| Aplazada | Media (5.4) | 0.20% | — | Advanced-woo-labels Advanced WOO LabelsAI | 1/10/2026 | 3/10/2026 | The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_meta_boxes' function in all versions up to, and including, 2.51. This makes it possible for authenticated attackers, with… | |
| En análisis | Alta (7.2) | 0.25% | — | Kiteworks Advanced FormsAI | 30/9/2026 | 1/10/2026 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions. | |
| Aplazada | Media (6.5) | 0.26% | — | Advanced Contact Form 7 DBAI | 23/9/2026 | 23/9/2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (8.8) | 0.65% | — | Openwrt Luci-app-advanced-rebootAI | 21/9/2026 | 24/9/2026 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in… | |
| Pendiente de análisis | Alta (8.8) | 0.78% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Pendiente de análisis | Crítica (9.3) | 0.70% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Pendiente de análisis | Crítica (9.3) | 0.70% | — | HP AdvanceAI | 16/9/2026 | 18/9/2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software. | |
| Aplazada | Media (6.4) | 0.21% | — | Ashstonestudios Advanced PopupsAI | 16/9/2026 | 16/9/2026 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Pendiente de análisis | Alta (8) | 0.36% | — | Oracle Advanced BenefitsAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.… | |
| Aplazada | Media (6.9) | 0.37% | — | Regularlabs Advanced Module ManagerAIRegularlabs Conditional ContentAIRegularlabs Content TemplaterAIRegularlabs RereplacerAI+1 | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is… | |
| Analizada | Media (6) | 0.27% | — | Amazon Advanced Jdbc Wrapper | 11/9/2026 | 16/9/2026 | Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database… | |
| Aplazada | Media (4.3) | 0.15% | — | Advanced-customized-prompts Advanced Customized PromptsAI | 11/9/2026 | 11/9/2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers. | |
| Aplazada | Media (5.4) | 0.13% | — | Advanced-customized-promptsAI | 11/9/2026 | 11/9/2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of… | |
| Aplazada | Crítica (9.8) | 0.28% | — | Advanced-customized-promptsAI | 11/9/2026 | 11/9/2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new… | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Media (4.3) | 0.21% | — | Advanced Contact Form 7 DBAI | 10/9/2026 | 10/9/2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above,… | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | IBM Verify Identity Access Advanced Access ControlAI | 4/9/2026 | 8/9/2026 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Alta (8.1) | 0.37% | — | Acfextended Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities… | |
| Aplazada | Alta (8.1) | 0.23% | — | Advancedcustomfields Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a… | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 31/8/2026 | When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently… | |
| Aplazada | Alta (7.2) | 1.0% | — | Silverstripe Advanced WorkflowAISilverstripeAI | 27/8/2026 | 9/9/2026 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When… | |
| Analizada | Media (6.8) | 0.27% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier |