Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)26%—Mitre CalderaAI24/2/202517/6/2026
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera…
AplazadaMedia (4.3)0.36%—Davidcramer Caldera Smtp MailerAI16/12/202417/6/2026
Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1.
AplazadaMedia (6.5)0.23%—Wpwebsitecreator WP Website CreatorAIWpformsAIFormidableAINinjaAI+218/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera wp-website-creator allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera:…
ModificadaAlta (8.8)0.39%—Gsheetconnector Caldera Forms Google Sheets Connector17/7/202317/6/2026
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaMedia (6.1)0.46%—Mitre Caldera17/10/202217/6/2026
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
ModificadaMedia (5.4)0.57%—Mitre Caldera17/10/202217/6/2026
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.
ModificadaMedia (6.1)0.46%—Mitre Caldera17/10/202217/6/2026
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
ModificadaMedia (6.1)1.2%—Calderaforms Caldera Forms18/4/202217/6/2026
The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.51%—Claderaform Calderawp License Manager12/4/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11.
ModificadaAlta (8.8)2.0%—Mitre Caldera12/1/202217/6/2026
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.
ModificadaMedia (6.1)1.1%—Mitre Caldera12/1/202217/6/2026
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
ModificadaAlta (8.1)1.2%—Mitre Caldera12/1/202217/6/2026
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
ModificadaAlta (8.8)20%—Mitre Caldera12/1/202217/6/2026
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell…
ModificadaAlta (8.8)2.1%—Mitre Caldera12/1/202217/6/2026
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).
ModificadaMedia (4.8)0.60%—Calderaforms Caldera Forms13/12/202117/6/2026
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.8)3.0%—Mitre Caldera12/7/202117/6/2026
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
ModificadaMedia (5.4)0.63%—Mitre Caldera19/6/202017/6/2026
CALDERA 2.7.0 allows XSS via the Operation Name box.
ModificadaMedia (5.3)1.4%—Mitre Caldera22/3/202017/6/2026
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
ModificadaMedia (4.8)4.4%—Calderalabs Caldera Forms20/4/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
ModificadaAlta (7.5)1.6%—Caldera8/5/201417/6/2026
The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.
ModificadaAlta (10)4.4%—Caldera8/5/201417/6/2026
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.
ModificadaAlta (7.5)1.5%—Caldera8/5/201417/6/2026
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.
ModificadaMedia (5)3.0%—Caldera8/5/201417/6/2026
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.
ModificadaAlta (7.5)1.3%—Umberto Caldera Easymoblog6/2/200716/6/2026
Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.
ModificadaMedia (5)2.1%—Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenserverSCO Unixware20/10/200316/6/2026
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.