Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.48% | — | Amentotech WorkreapAI | 6/10/2026 | 6/10/2026 | Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | |
| Aplazada | Media (5.4) | 0.34% | — | Filamentphp FilamentAI | 1/10/2026 | 6/10/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Parallax Filament-commentsAI | 14/9/2026 | 24/9/2026 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including… | |
| Aplazada | Baja (3.7) | 0.46% | — | Filamentphp FilamentAI | 1/9/2026 | 9/9/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating canAccessPanel(). For an account that canAccessPanel() denies, submitting the correct… | |
| Aplazada | Media (6.5) | 0.45% | — | Filamentphp FilamentAI | 1/9/2026 | 9/9/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key derived from both the app authentication secret and the submitted TOTP… | |
| Aplazada | Alta (8.1) | 0.55% | — | Filamentphp FilamentAI | 24/8/2026 | 9/9/2026 | Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not… | |
| Aplazada | Alta (7.6) | 0.28% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an attacker could plant… | |
| Aplazada | Alta (7.4) | 0.30% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA.… | |
| Aplazada | Media (6.5) | 0.34% | 💥 PoC | LaravelAIFilamentphp FilamentAILaravel LivewireAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as… | |
| Aplazada | Media (6.4) | 0.25% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plant malicious HTML or… | |
| Aplazada | Media (5.3) | 0.34% | — | Filamentphp FilamentAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an account exists for… | |
| Aplazada | Media (6.5) | 0.30% | — | Filament ActionsAINextcloud TablesAI | 22/6/2026 | 23/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and… | |
| Aplazada | Alta (7.3) | 0.24% | — | Firmament Autopilot Fmt-firmwareAI | 13/5/2026 | 17/6/2026 | Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c. | |
| Aplazada | Media (5.5) | 0.41% | — | Dameng MuucmfAI | 19/4/2026 | 17/6/2026 | A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Baja (2.1) | 0.45% | — | Dameng MuucmfAI | 26/3/2026 | 17/6/2026 | A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.45% | — | Dameng MuucmfAI | 26/3/2026 | 17/6/2026 | A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The… | |
| Aplazada | Baja (2.1) | 0.45% | — | Dameng100 MuucmfAI | 26/3/2026 | 17/6/2026 | A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the file channel/admin.Account/autoReply.html. Such manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.45% | — | Dameng MuucmfAI | 26/3/2026 | 17/6/2026 | A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted… | |
| Analizada | Media (5.4) | 0.36% | — | Filamentphp Filament | 20/3/2026 | 17/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If there is a lack of validation for the data in the columns that use… | |
| Aplazada | Crítica (9.8) | 0.62% | — | Amenotech Workreap CoreAI | 22/1/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This issue affects Workreap Core: from n/a through <= 3.4.1. | |
| Aplazada | Alta (8.5) | 0.36% | — | Amentotech WorkreapAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL Injection.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.6. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Amenotech TuturnAI | 18/12/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6. | |
| Aplazada | Media (6.5) | 0.35% | — | Amentotech TuturnAI | 18/12/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue affects Tuturn: from n/a before 3.6. | |
| Analizada | Alta (8.1) | 0.34% | — | Filamentphp Filament | 10/12/2025 | 17/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also… | |
| Aplazada | Alta (7.7) | 0.43% | — | Amentotech WorkreapAI | 22/10/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5. |