Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.27% | — | Limesurvey Community EditionAI | 2/10/2026 | 2/10/2026 | An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript… | |
| Aplazada | Alta (7.1) | 0.24% | — | Limesurvey Community EditionAI | 29/9/2026 | 30/9/2026 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request… | |
| Aplazada | Alta (7.4) | 0.39% | — | Limesurvey Community EditionAI | 23/9/2026 | 23/9/2026 | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. | |
| Aplazada | Media (5.3) | 0.40% | — | Fastgpt Community EditionAI | 31/8/2026 | 1/9/2026 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all… | |
| Aplazada | Media (5.1) | 0.40% | — | Limesurvey Community EditionAI | 27/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without… | |
| Aplazada | Media (4.8) | 0.41% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | |
| Aplazada | Alta (7.4) | 0.46% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects… | |
| Aplazada | Alta (7.2) | 0.24% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5. | |
| Aplazada | Alta (8.4) | 0.26% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data… | |
| Aplazada | Alta (7.1) | 0.40% | — | Dradis Community EditionAI | 25/8/2026 | 24/9/2026 | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an… | |
| Aplazada | Alta (8.6) | 1.5% | — | Otrs Community EditionAI | 20/8/2026 | 24/9/2026 | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are… | |
| Aplazada | Alta (7.2) | 0.47% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into… | |
| Aplazada | Alta (7.4) | 0.46% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |
| Aplazada | Media (6) | 0.38% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. | |
| Aplazada | Alta (8.5) | 0.53% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |
| Aplazada | Media (5.1) | 0.31% | — | Saurus CMS Community EditionAI | 13/8/2026 | 31/8/2026 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can… | |
| Aplazada | Media (5.9) | 0.43% | — | Fastnetmon Community EditionAI | 2/6/2026 | 22/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without… | |
| Aplazada | Media (6.5) | 0.44% | — | Fastnetmon Community EditionAI | 26/5/2026 | 24/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end… | |
| Aplazada | Media (4.8) | 0.18% | — | Arangodb Community EditionAIArangodb AardvarkAI | 15/2/2026 | 17/6/2026 | ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI | 12/2/2026 | 17/6/2026 | Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network… | |
| Aplazada | Baja (2) | 0.22% | — | Cloudpanel Community EditionAI | 30/12/2025 | 5/10/2026 | A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (4.3) | 0.33% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Aplazada | Crítica (10) | 0.64% | — | Saurus CMS Community EditionAI | 19/8/2025 | 5/7/2026 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution. | |
| Aplazada | Alta (8.1) | 0.36% | — | Opennebula Community EditionAIOpennebula Enterprise EditionAI | 3/8/2025 | 17/6/2026 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their… | |
| Aplazada | Crítica (9.1) | 0.57% | — | Saurus CMS Community EditionAI | 1/8/2025 | 17/6/2026 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to… |