Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.31% | — | MicroweberAI | 23/9/2026 | 24/9/2026 | Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker… | |
| Aplazada | Alta (7.4) | 0.21% | — | ASR CraneAICrowdstrike FalconAI | 23/9/2026 | 23/9/2026 | NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c. | |
| Aplazada | Alta (8.8) | 0.46% | — | Pdfcrowd Save AS PDFAI | 19/9/2026 | 21/9/2026 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options… | |
| Pendiente de análisis | Alta (8.8) | 0.08% | — | Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI | 15/9/2026 | 18/9/2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.… | |
| Aplazada | Media (6.4) | 0.22% | — | Themeum WP CrowdfundingAI | 9/9/2026 | 9/9/2026 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (4.9) | 0.26% | — | Themeum WP CrowdfundingAI | 9/9/2026 | 9/9/2026 | The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in… | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Atlassian Crowd Data CenterAI | 18/8/2026 | 26/8/2026 | This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as… | |
| Aplazada | Media (4.3) | 0.25% | — | Themeum WP CrowdfundingAI | 12/8/2026 | 26/8/2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission. | |
| Aplazada | Media (4.3) | 0.27% | — | Themeum WP CrowdfundingAI | 12/8/2026 | 26/8/2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store. | |
| Aplazada | Media (4.3) | 0.25% | — | Themeum WP CrowdfundingAI | 12/8/2026 | 26/8/2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to its backers, allowing any authenticated users such as Subscribers to alter other users' campaigns. | |
| Aplazada | Media (4.8) | 0.27% | — | Microweber CMSAI | 3/8/2026 | 10/9/2026 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent… | |
| Aplazada | Alta (8.6) | 0.92% | — | Microweber CMSAI | 24/7/2026 | 28/7/2026 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks… | |
| Aplazada | Alta (8.7) | 3.4% | — | Microweber CMSAI | 23/7/2026 | 30/7/2026 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the… | |
| Aplazada | Alta (7.2) | 0.37% | — | CrowdsecAI | 16/7/2026 | 17/7/2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a request body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests using Transfer-Encoding: chunked and HTTP/2 requests without a content-length header produced an… | |
| Aplazada | Alta (8.2) | 0.51% | — | CrowdsecAI | 16/7/2026 | 17/7/2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with DefaultDecompressHandle globally in pkg/apiserver/controllers/controller.go, causing /v1/watchers and /v1/watchers/login to decompress unauthenticated gzip-compressed JSON request bodies… | |
| Aplazada | Media (5.5) | 0.53% | — | MicroweberAI | 15/6/2026 | 24/7/2026 | A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.3) | 0.47% | — | Helpfulcrowd Product ReviewsAI | 9/6/2026 | 23/7/2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Crowcpp CrowAI | 2/6/2026 | 22/7/2026 | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Pendiente de análisis | Crítica (9.8) | 0.84% | — | Crowdstrike LogscaleAI | 21/4/2026 | 17/6/2026 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ancorathemes Crown ARTAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11. | |
| Analizada | Media (6.1) | 0.32% | — | Microweber | 5/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the… | |
| Analizada | Media (6.1) | 0.31% | — | Microweber | 5/2/2026 | 17/6/2026 | Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was reported to the… | |
| Analizada | Alta (7.9) | 0.33% | — | Atlassian Crowd | 28/1/2026 | 17/6/2026 | This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. * Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3 |