Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.28% | — | Gedelumbung HospitalmanagementAISunhater KcfinderAI | 29/9/2026 | 30/9/2026 | A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the… | |
| Aplazada | Alta (8.6) | 0.45% | — | Album Cover FinderAI | 12/9/2026 | 14/9/2026 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 0.90% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent… | |
| Aplazada | Media (5.4) | 0.18% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped… | |
| Aplazada | Alta (8.6) | 0.55% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects… | |
| Aplazada | Alta (7.1) | 0.25% | — | Superstorefinder Super Store FinderAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | |
| En análisis | Baja (3.1) | 0.29% | — | Tanium FindingsAI | 19/8/2026 | 1/9/2026 | Tanium addressed a compression bomb vulnerability in Findings. | |
| Aplazada | Alta (8.8) | 0.42% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Alta (8.7) | 0.44% | — | FlawfinderAI | 11/8/2026 | 9/9/2026 | Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Openlibraryfoundation VufindAI | 6/8/2026 | 9/9/2026 | Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function.… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Superstorefinder Super Store FinderAI | 3/8/2026 | 31/8/2026 | The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. | |
| Aplazada | Alta (7.5) | 0.46% | — | Find-my-wayAI | 28/7/2026 | 30/7/2026 | find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find()… | |
| Aplazada | Baja (1.9) | 1.1% | — | Bahmutov Find-cypress-specsAI | 23/7/2026 | 23/7/2026 | A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Apple Find MYAI | 21/7/2026 | 23/7/2026 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of… | |
| Aplazada | Alta (8.8) | 0.44% | — | ElfinderAI | 27/5/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through… | |
| Analizada | Alta (8.9) | 2.7% | — | Std42 Elfinder | 23/4/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that… | |
| Aplazada | Media (5.4) | 0.24% | — | Codesolz Better Find AND ReplaceAI | 16/4/2026 | 17/6/2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Alta (8.7) | 0.57% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files. | |
| Aplazada | Crítica (9.3) | 0.98% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Aplazada | Media (5.3) | 0.33% | — | Doofinder FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13. | |
| Aplazada | Crítica (9.3) | 0.46% | — | DBTAIPeter Evans Find CommentAI | 7/4/2026 | 24/7/2026 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml, the prep job uses peter-evans/find-comment to search for an existing comment… | |
| Aplazada | Alta (8.1) | 0.52% | — | Elated-themes FindallAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through <= 1.4. | |
| Aplazada | Alta (8.7) | 0.39% | — | Chamilo LMSAIElfinderAI | 20/2/2026 | 17/6/2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing… | |
| Aplazada | Media (4.6) | 0.35% | — | Office Product KEY FinderAI | 11/2/2026 | 17/6/2026 | Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash. |