Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.33% | — | Approval APPAI | 18/9/2026 | 18/9/2026 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check when the etag parameter was present and non-empty in the request. An… | |
| Aplazada | Alta (8.6) | 0.53% | — | Woocommerce File ApprovalAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | |
| Analizada | Baja (3.3) | 0.17% | — | Nextcloud Approval | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in version 2.7.2. | |
| Analizada | Media (6.5) | 0.49% | — | Nextcloud Approval | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation,… | |
| Analizada | Crítica (9.8) | 2.2% | — | Ridvay Auto-approval Module | 31/3/2026 | 25/7/2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account… | |
| Analizada | Crítica (9.8) | 2.2% | — | Ridvay Auto-approval Module | 31/3/2026 | 25/7/2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account… | |
| Analizada | Baja (2.7) | 0.31% | — | Nextcloud Approval | 5/12/2025 | 17/6/2026 | The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file by using the numeric file id. This vulnerability is fixed in 1.3.1… | |
| Aplazada | Media (5.3) | 0.15% | — | Publish ApprovalAI | 11/9/2025 | 17/6/2026 | The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the publish_save_option function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request… | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Alta (7.5) | 0.54% | — | Infodrom E-invoice Approval System | 25/7/2023 | 17/6/2026 | Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701. | |
| Modificada | Crítica (9.8) | 0.63% | — | Infodrom E-invoice Approval System | 25/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701. | |
| Modificada | Alta (7.5) | 0.74% | — | Infodoc Document On-line Submission AND Approval System | 20/7/2023 | 17/6/2026 | InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its HTML to PDF conversion function, and allowing an unauthenticated attackers to load remote or local resources through HTML tags such as iframe. This vulnerability allows unauthenticated remote… | |
| Modificada | Crítica (9.8) | 0.93% | — | Infodoc Document On-line Submission AND Approval System | 20/7/2023 | 17/6/2026 | It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable… | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Approvals Management | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Approvals Management product of Oracle E-Business Suite (component: AME Page rendering). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Approvals Management. Successful… | |
| Modificada | Media (6.4) | 1.7% | — | Oracle Approvals Management | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Approvals Management component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to AME Page rendering. | |
| Modificada | Media (6.8) | 1.0% | — | Member Approval Plugin Project Member Approval | 11/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings to their default and disable registration approval via a request to wp-admin/options-general.php. | |
| Modificada | Media (4.3) | 1.6% | — | Slickremix Design Approval System Plugin | 17/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin before 3.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter. |