Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.49% | — | Bluewavelabs CheckmateAI | 3/9/2026 | 10/9/2026 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and… | |
| Aplazada | Alta (7.2) | 0.58% | — | Bluewavelabs CheckmateAI | 27/8/2026 | 1/9/2026 | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint. | |
| Aplazada | Alta (7.5) | 0.48% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete… | |
| Aplazada | Media (4.9) | 0.59% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue… | |
| Aplazada | Alta (7.5) | 0.62% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through… | |
| Aplazada | Media (5.3) | 0.42% | — | Bluewavelabs CheckmateAI | 10/8/2026 | 28/8/2026 | A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered… | |
| Aplazada | Alta (8.2) | 0.33% | — | Bluewavelabs CheckmateAI | 6/8/2026 | 26/8/2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the… | |
| Analizada | Alta (8.1) | 0.36% | — | Bluewavelabs Checkmate | 20/3/2026 | 17/6/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to… | |
| Analizada | Media (5.3) | 0.41% | — | Bluewavelabs Checkmate | 7/3/2026 | 17/6/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url endpoint. The… | |
| Aplazada | Media (5) | 0.34% | — | Bluewavelabs CheckmateAI | 15/5/2025 | 17/6/2026 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint. | |
| Aplazada | Alta (8.8) | 0.50% | — | Bluewavelabs CheckmateAI | 10/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter. | |
| Aplazada | Alta (8.1) | 0.50% | — | Bluewavelabs CheckmateAI | 4/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. |