Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

4208 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.4)0.22%—Wpmobile APPAI3/10/20263/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.19%—JetappointmentAI2/10/20262/10/2026
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaCrítica (9.8)0.49%—Amauri Wpmobile.appAI2/10/20262/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate…
AplazadaMedia (6.9)0.26%—Wormhole.appAI1/10/20261/10/2026
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
AplazadaAlta (7.5)0.43%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom…
AplazadaMedia (6.5)0.32%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (5.3)0.25%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
AplazadaMedia (6.5)0.21%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
AplazadaMedia (6.9)0.24%—Amauri IO Wpmobile APPAI30/9/202630/9/2026
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
AplazadaAlta (7.5)0.65%—Simply Schedule AppointmentsAI30/9/202630/9/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files…
Pendiente de análisisCrítica (10)1.2%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Pendiente de análisisAlta (8.1)0.68%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Pendiente de análisisAlta (7.6)0.46%—Zohocorp Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Pendiente de análisisAlta (7.1)0.78%—Zoho Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Pendiente de análisisAlta (8.8)0.68%—Zohocorp Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Pendiente de análisisAlta (8.8)2.0%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
Pendiente de análisisAlta (8.8)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Pendiente de análisisAlta (7.1)0.30%—Canva Mobile APPAI21/9/202621/9/2026
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
AplazadaMedia (4.3)0.33%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered…
AplazadaAlta (8.8)0.52%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered…
AplazadaMedia (5.4)0.36%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email…
Pendiente de análisisMedia (4.8)0.18%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Pendiente de análisisMedia (6.5)0.38%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAI18/9/202622/9/2026
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Pendiente de análisisMedia (6.5)0.23%—IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI18/9/202622/9/2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.