Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.2) | 0.29% | — | Backdropcms Backdrop CMSAI | 2/10/2026 | 5/10/2026 | Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site… | |
| Aplazada | Alta (8.6) | 0.45% | — | Price Drop Alert FOR WOO CommerceAI | 18/9/2026 | 18/9/2026 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Media (5.9) | 0.53% | — | Cyberdrop DLAI | 15/9/2026 | 30/9/2026 | Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact member of SUPPORTED_DOMAINS, and then reuses that input host for API requests. When a Pixeldrain API key is configured,… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Drag AND Drop File Upload FOR Elementor FormsAI | 10/9/2026 | 10/9/2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled… | |
| Analizada | Media (5.3) | 0.31% | — | Lakedrops Digital Signage Framework | 2/9/2026 | 16/9/2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | |
| Aplazada | Alta (8.1) | 0.54% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. | |
| Aplazada | Baja (3.5) | 0.24% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Pendiente de análisis | Alta (7.6) | 0.22% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML response for the SP-initiated flow by… | |
| Pendiente de análisis | Crítica (9.1) | 0.60% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector is a no-op. The /3… | |
| Aplazada | Baja (3.7) | 0.31% | — | Freedom OF THE Press Foundation Securedrop ClientAIFreedom OF THE Press Foundation Securedrop ServerAIFreedom OF THE Press Foundation Securedrop-proxyAI | 20/8/2026 | 18/9/2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has… | |
| Aplazada | Alta (7.1) | 0.29% | — | Eprolo DropshippingAI | 20/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Easy Integration FOR DropboxAI | 4/8/2026 | 26/8/2026 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account… | |
| Aplazada | Media (5.3) | 0.39% | — | Kali Forms Contact Form AND Drag AND Drop BuilderAI | 15/7/2026 | 15/7/2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress… | |
| Analizada | Media (5.4) | 0.23% | — | Flowdrop Project Flowdrop | 10/7/2026 | 14/7/2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. | |
| Analizada | Media (5.4) | 0.23% | — | Flowdrop Project Flowdrop | 10/7/2026 | 14/7/2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. | |
| Aplazada | Alta (7.5) | 0.47% | — | Sureforms Drag AND Drop Form BuilderAI | 10/7/2026 | 14/7/2026 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-controlled POST data in the 'create_payment_intent' and… | |
| Aplazada | Media (4.8) | 0.26% | — | ALD Dropshipping AND FulfillmentAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Syncee Premium Dropshipping AND WholesaleAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions. | |
| Aplazada | Media (6.1) | 0.29% | — | EntredroppersAI | 24/6/2026 | 25/6/2026 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (8.8) | 0.49% | — | Raindropsinfotech Twitch TV | 19/6/2026 | 21/8/2026 | Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL… | |
| Aplazada | Media (6.5) | 0.33% | — | Opmc Woocommerce DropshippingAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | MicdropAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions. | |
| Aplazada | Alta (8.1) | 0.35% | — | Food DropAI | 17/6/2026 | 5/10/2026 | Unauthenticated Local File Inclusion in Food Drop <= 1.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7 Drag AND Drop Multiple File UploadAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. |