Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
4208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.4) | 0.22% | — | Wpmobile APPAI | 3/10/2026 | 3/10/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.19% | — | JetappointmentAI | 2/10/2026 | 2/10/2026 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Amauri Wpmobile.appAI | 2/10/2026 | 2/10/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate… | |
| Aplazada | Media (6.9) | 0.26% | — | Wormhole.appAI | 1/10/2026 | 1/10/2026 | Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP. | |
| Aplazada | Alta (7.5) | 0.43% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom… | |
| Aplazada | Media (6.5) | 0.32% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.25% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | |
| Aplazada | Media (6.9) | 0.24% | — | Amauri IO Wpmobile APPAI | 30/9/2026 | 30/9/2026 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | |
| Aplazada | Alta (7.5) | 0.65% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files… | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. | |
| Pendiente de análisis | Alta (8.1) | 0.68% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. | |
| Pendiente de análisis | Alta (7.6) | 0.46% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.78% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. | |
| Pendiente de análisis | Alta (7.1) | 0.30% | — | Canva Mobile APPAI | 21/9/2026 | 21/9/2026 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session. | |
| Aplazada | Media (4.3) | 0.33% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered… | |
| Aplazada | Media (5.4) | 0.36% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email… | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | IBM Websphere Application ServerAIIBM Websphere Application Server LibertyAI | 18/9/2026 | 22/9/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. |