Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.39% | — | GardenerAI | 22/9/2026 | 23/9/2026 | Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount… | |
| Aplazada | Alta (8.7) | 0.43% | — | GardensAI | 3/9/2026 | 9/9/2026 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active… | |
| Aplazada | Alta (7.7) | 0.30% | — | GardensAI | 3/9/2026 | 9/9/2026 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's… | |
| Aplazada | Alta (8.7) | 0.41% | — | GardensAI | 3/9/2026 | 9/9/2026 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals while an escrow is disputed, but the… | |
| Pendiente de análisis | Media (5.1) | 0.16% | — | Canon MY Image GardenAI | 29/5/2026 | 21/7/2026 | Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization. | |
| Aplazada | Media (5.9) | 0.24% | — | Ggnome Garden Gnome PackageAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chief Gnome Garden Gnome Package garden-gnome-package allows DOM-Based XSS.This issue affects Garden Gnome Package: from n/a through <= 2.4.1. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Asia GardenAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.30% | — | Wisdomgarden TronclassAI | 23/2/2026 | 17/6/2026 | Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers to modify a specific parameter to obtain a course invitation code, thereby joining any course. | |
| Aplazada | Media (5.3) | 0.23% | — | Engotheme Plant Gardening HouseplantsAI | 7/1/2026 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through 1.0.0. | |
| Analizada | Alta (8.4) | 0.24% | — | Linuxfoundation Gardenctl | 12/12/2025 | 30/9/2026 | gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with administrative privileges for a Gardener project to craft malicious credential… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Gardener Extensions AWSAIGardener Extensions AzureAIGardener Extensions OpenstackAIGardener Extensions GCPAI+1 | 25/9/2025 | 17/6/2026 | Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.0, OpenStack providers prior to version 1.49.0, and GCP providers prior to… | |
| Aplazada | Media (5.3) | 0.27% | — | Wisdomgarden TronclassAI | 19/9/2025 | 17/6/2026 | Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other users' files. | |
| Analizada | Crítica (9.9) | 0.45% | — | Gardener | 19/5/2025 | 17/6/2026 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to… | |
| Modificada | Crítica (9.9) | 0.65% | — | Gardener | 19/5/2025 | 17/6/2026 | Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 that could allow a user with administrative privileges for a Gardener project to obtain control over the seed… | |
| Aplazada | Crítica (9.9) | 0.71% | — | Gardener External DNS ManagementAIGardener Extension Shoot DNS ServiceAI | 19/5/2025 | 17/6/2026 | Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered in Gardener's External DNS Management prior to version 0.23.6 that could allow a user with administrative privileges for a Gardener project or a user with administrative… | |
| Analizada | Media (6.1) | 0.34% | — | Karacsi Maci Banner Garden | 4/2/2025 | 17/6/2026 | The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users. | |
| Aplazada | Alta (8.8) | 0.82% | — | Ggnome Garden Gnome PackageAI | 8/1/2025 | 17/6/2026 | The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts 'ggpkg' files that have been uploaded in all versions up to, and including, 2.3.0. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.77% | — | Chris Gardenberg Eduadmin BookingAI | 16/12/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmin Booking eduadmin-booking allows PHP Local File Inclusion.This issue affects EduAdmin Booking: from n/a through <= 5.2.0. | |
| Analizada | Alta (8.8) | 0.50% | — | Plugingarden WP Easy Gallery | 1/10/2024 | 17/6/2026 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (4.3) | 0.28% | — | Plugingarden WP Easy Gallery | 25/9/2024 | 17/6/2026 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.9) | 0.48% | — | Plugingarden WP Easy Gallery | 25/9/2024 | 17/6/2026 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Analizada | Media (5.4) | 0.41% | — | Ggnome Garden Gnome Package | 24/9/2024 | 17/6/2026 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.46% | — | Wisdomgarden Tronclass | 15/7/2024 | 17/6/2026 | The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL. | |
| Modificada | Media (5.4) | 0.55% | — | Ggnome Garden Gnome Package | 22/11/2023 | 17/6/2026 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shortcode in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.5) | 0.85% | — | Wisdomgarden Tronclass Ilearn | 3/11/2023 | 17/6/2026 | NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files. |