Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
632 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Metagauss ProfilegridAI | 1/10/2026 | 1/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Boldgrid Post AND Page BuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | |
| Aplazada | Baja (3.5) | 0.14% | — | Pickplugins Post GridAI | 24/9/2026 | 24/9/2026 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection… | |
| Aplazada | Media (6.5) | 0.17% | — | Pickplugins Post GridAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Radiustheme THE Post GridAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Post Grid Gutenberg BlocksAI | 23/9/2026 | 23/9/2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,… | |
| Aplazada | Alta (8.1) | 0.40% | — | Diracgrid DiracAI | 15/9/2026 | 30/9/2026 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and… | |
| Aplazada | Crítica (9.9) | 1.2% | — | Diracgrid DiracAI | 15/9/2026 | 30/9/2026 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated… | |
| Aplazada | Crítica (9.9) | 0.86% | — | Diracgrid DiracAI | 15/9/2026 | 30/9/2026 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to… | |
| Aplazada | Alta (7.2) | 0.50% | — | Boldgrid W3 Total CacheAI | 5/9/2026 | 8/9/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Baja (2.3) | 0.25% | — | Netapp StoragegridAI | 28/8/2026 | 1/9/2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service. | |
| Aplazada | Media (6.4) | 0.33% | — | Image Photo Gallery Final Tiles GridAI | 22/8/2026 | 24/8/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.8) | 0.43% | — | Post Grid Slider Carousel UltimateAI | 22/8/2026 | 26/8/2026 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any… | |
| Aplazada | Alta (7.3) | 0.17% | — | Jxl-oxide Jxl-gridAI | 19/8/2026 | 18/9/2026 | jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing… | |
| Aplazada | Crítica (10) | 0.57% | — | Boldgrid W3 Total CacheAI | 19/8/2026 | 26/8/2026 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the… | |
| Aplazada | Alta (8.8) | 0.42% | — | Themeone THE GridAI | 18/8/2026 | 1/9/2026 | Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0. | |
| Aplazada | Alta (7.2) | 0.43% | — | Boldgrid W3 Total CacheAI | 14/8/2026 | 14/8/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.5) | 0.43% | — | Boldgrid Total UpkeepAI | 12/8/2026 | 3/9/2026 | The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database.… | |
| Aplazada | Alta (8.2) | 0.37% | — | Boldgrid Total UpkeepAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | |
| Aplazada | Media (5.3) | 0.35% | — | Metagauss ProfilegridAI | 6/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Aplazada | Media (4.3) | 0.27% | — | Metagauss ProfilegridAI | 3/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones. | |
| Aplazada | Media (4.3) | 0.25% | — | Metagauss ProfilegridAI | 2/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. | |
| Aplazada | Alta (7.5) | 0.41% | — | Metagauss ProfilegridAI | 30/7/2026 | 30/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists,… |