Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Infusedwoo PROAI | 25/8/2026 | 27/8/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users… | |
| Aplazada | Alta (7.5) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages,… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a… | |
| Aplazada | Alta (8.8) | 0.51% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible… | |
| Analizada | Media (5.3) | 0.15% | — | Redwoodjs Redwoodsdk | 8/5/2026 | 17/6/2026 | RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the victim's session… | |
| Analizada | Alta (8.1) | 0.19% | — | Redwoodjs Redwoodsdk | 7/4/2026 | 24/7/2026 | RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because… | |
| Modificada | Crítica (9.8) | 0.78% | — | Thedaylightstudio DwooThedaylightstudio Fuel CMS | 26/3/2026 | 5/7/2026 | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | |
| Modificada | Alta (7.2) | 32% | — | Redwood Jscape MFT | 7/9/2023 | 17/6/2026 | Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface | |
| Modificada | Media (5.3) | 1.9% | — | Redwood Report2web | 5/2/2021 | 17/6/2026 | A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter. | |
| Modificada | Media (6.1) | 7.5% | — | Redwood Report2web | 5/2/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter. | |
| Modificada | Crítica (9.8) | 6.2% | — | Redwoodhq | 19/6/2019 | 17/6/2026 | RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call. | |
| Modificada | Media (5.9) | 1.9% | — | Maradns Project MaradnsDeadwood Project Deadwood | 20/3/2018 | 17/6/2026 | Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to missing input validation. | |
| Modificada | Media (5.9) | 1.7% | — | Maradns Project MaradnsDeadwood Project Deadwood | 20/3/2018 | 17/6/2026 | Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwood, related to a logic error. | |
| Modificada | Alta (8.8) | 1.6% | — | Redwood SAP Business Process Automation | 14/3/2018 | 17/6/2026 | SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | Redwood SAP Business Process Automation | 14/3/2018 | 17/6/2026 | Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Media (4.3) | 1.5% | — | Redwood SAP Business Process Automation | 14/3/2018 | 17/6/2026 | SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. | |
| Modificada | Alta (7.5) | 2.3% | — | Toddwoolums ASP Download | 21/4/2009 | 16/6/2026 | Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request. | |
| Modificada | Media (5) | 2.1% | — | Toddwoolums Todd Woolums ASP News Management | 28/11/2008 | 16/6/2026 | Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | — | Toddwoolums Todd Woolums ASP News Management | 28/11/2008 | 16/6/2026 | SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute arbitrary SQL commands via the newsID parameter. |