Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.49%—Bluewavelabs CheckmateAI3/9/202610/9/2026
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and…
AplazadaAlta (7.2)0.58%—Bluewavelabs CheckmateAI27/8/20261/9/2026
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
AplazadaAlta (7.5)0.48%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete…
AplazadaMedia (4.9)0.59%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue…
AplazadaAlta (7.5)0.62%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through…
AplazadaMedia (5.3)0.42%—Bluewavelabs CheckmateAI10/8/202628/8/2026
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered…
AplazadaAlta (8.2)0.33%—Bluewavelabs CheckmateAI6/8/202626/8/2026
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the…
AnalizadaAlta (8.1)0.36%—Bluewavelabs Checkmate20/3/202617/6/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to…
AnalizadaMedia (5.3)0.41%—Bluewavelabs Checkmate7/3/202617/6/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url endpoint. The…
AplazadaMedia (5)0.34%—Bluewavelabs CheckmateAI15/5/202517/6/2026
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
AplazadaAlta (8.8)0.50%—Bluewavelabs CheckmateAI10/5/202517/6/2026
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
AplazadaAlta (8.1)0.50%—Bluewavelabs CheckmateAI4/5/202517/6/2026
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.