Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.14%—Blacklist ManagerAI30/9/202630/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.
AplazadaMedia (5.4)0.17%—Blacklist Manager FOR WoocommerceAI28/9/202628/9/2026
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
AplazadaMedia (5.3)0.22%—Black CandyAI24/9/202629/9/2026
Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance. Attackers can query the SearchController or Search::PlaylistsController endpoints with blank or targeted search parameters to retrieve playlist…
AplazadaBaja (2)2.2%—Magicblack Maccms10AI14/9/202616/9/2026
A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command…
AnalizadaMedia (6.1)0.58%—Dangerblack N8n-node-sqlite327/8/202623/9/2026
n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a…
AplazadaMedia (5.5)0.69%—Blackms AistackAI27/8/202629/8/2026
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed remotely. The exploit is publicly…
Pendiente de análisisAlta (7.5)0.19%—Black Duck Blackduck-c-cppAI24/8/20261/9/2026
Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the scan. Filesystem paths encountered while…
Pendiente de análisisAlta (7.1)0.18%—Black Duck Blackduck-c-cppAI24/8/20261/9/2026
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture…
AplazadaAlta (7.1)0.25%—Maspik Spam BlacklistAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
AnalizadaMedia (5.9)0.26%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
AnalizadaAlta (8.6)0.25%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.
AnalizadaBaja (3.1)0.26%—Blacklanternsecurity Bbot8/7/202619/8/2026
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location…
AnalizadaBaja (3.1)0.38%—Blacklanternsecurity Bbot8/7/202619/8/2026
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for…
AplazadaBaja (3.1)0.17%—Docker RegistryAIBlacklanternsecurity BbotAI17/6/202622/6/2026
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary…
AplazadaMedia (6.5)0.18%—Skywarrior BlackfyreAI8/4/202624/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This issue affects Blackfyre: from n/a through <= 2.5.4.
AplazadaAlta (7.2)0.51%—Plugin-planet Blackhole FOR BAD BotsAI26/3/202617/6/2026
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when capturing bot data (which strips HTML tags…
ModificadaAlta (8.7)0.72%—Python Black12/3/20263/8/2026
Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker…
AnalizadaAlta (8.7)0.64%—Python Black11/3/202617/6/2026
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct URL reference to a…
ModificadaCrítica (9.3)0.99%—Blackbeartechhive Atop Ehg2408 FirmwareBlackbeartechhive Atop Ehg2408-2sfp Firmware9/3/20267/7/2026
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
AplazadaAlta (8.5)0.16%—Blackmoon FTP ServerAI11/2/202617/6/2026
BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account…
AnalizadaCrítica (9.8)3.8%—Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+15920/1/202617/6/2026
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
AplazadaMedia (4.4)0.30%—CM Email BlacklistAI17/1/202617/6/2026
The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'black_email' parameter in all versions up to, and including, 1.6.2. This is due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaMedia (6.3)0.36%—Neoteroi Blacksheep14/1/202617/6/2026
BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create…
AnalizadaAlta (8.6)0.91%—Blackcat-cms Blackcat CMS15/12/202517/6/2026
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a…
AnalizadaMedia (5.1)0.24%—Blackcat-cms Blackcat CMS15/12/202517/6/2026
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.