Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.59% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the purge, no_order_purge, or delete_guests commands. An authenticated administrator with read-only customer privileges can… | |
| Aplazada | Alta (7.2) | 1.4% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited… | |
| Aplazada | Alta (7.2) | 1.4% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can… | |
| Aplazada | Media (4.8) | 1.1% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator… | |
| Pendiente de análisis | Media (6.1) | 0.90% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI… | |
| Aplazada | Media (5.4) | 0.38% | — | CubecartAI | 17/9/2026 | 23/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator… | |
| Aplazada | Media (5.3) | 0.33% | — | CubecartAI | 17/9/2026 | 24/9/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an… | |
| Aplazada | Alta (7.1) | 0.28% | — | Spacedot Acubesat OBCAI | 24/8/2026 | 9/9/2026 | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message. | |
| Aplazada | Alta (7.5) | 0.46% | — | Spacedot Acubesat OBCAI | 24/8/2026 | 9/9/2026 | A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message. | |
| Aplazada | Alta (7.5) | 0.46% | — | Spacedot Acubesat OBCAI | 24/8/2026 | 9/9/2026 | An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Media (6.5) | 0.36% | — | Spacedot Acubesat OBCAI | 24/8/2026 | 9/9/2026 | An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message. | |
| Analizada | Media (4.3) | 0.39% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. | |
| Analizada | Alta (8.8) | 0.50% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.8) | 0.56% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540,… | |
| Analizada | Media (4.3) | 0.37% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | |
| Analizada | Crítica (9.8) | 0.58% | — | Roundcube Webmail | 17/8/2026 | 10/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | |
| Analizada | Alta (7.1) | 2.3% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. | |
| Analizada | Media (5.8) | 0.47% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.4) | 0.30% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | |
| Analizada | Alta (7.2) | 0.44% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |
| Analizada | Alta (8.8) | 1.1% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. | |
| Aplazada | Alta (8.5) | 0.36% | — | CubewpAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Aplazada | Media (4.9) | 0.38% | — | Cubewp FrameworkAI | 10/8/2026 | 26/8/2026 | The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata (including that of other users' draft,… |