Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.65% | — | Input LeapAI | 25/9/2026 | 30/9/2026 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message. | |
| Aplazada | Crítica (9.8) | 0.93% | — | Sogou Input MethodAI | 16/9/2026 | 22/9/2026 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Dynamic Input Field GeneratorAI | 21/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Dynamic Input Field Generator Using Html CSS AND PHPAI | 21/8/2026 | 24/8/2026 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Tychesoftwares Product Input Fields FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on… | |
| Aplazada | Media (5.3) | 0.45% | — | Robinherbots InputmaskAI | 18/7/2026 | 20/7/2026 | A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in improperly controlled modification of object… | |
| Aplazada | Media (6.9) | 0.15% | — | InputsharingAI | 10/7/2026 | 10/7/2026 | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data. | |
| Aplazada | Media (5.4) | 0.23% | — | Deck9 InputAI | 15/6/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Aplazada | Alta (8.1) | 0.41% | — | Deck9 InputAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request. | |
| Analizada | Crítica (9.8) | 0.53% | — | Freedesktop Libinput | 4/6/2026 | 22/7/2026 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | |
| Pendiente de análisis | Alta (7) | 0.11% | — | AMD General-purpose Input Output ControllerAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Sanitize OR Validate This InputAI | 6/4/2026 | 24/7/2026 | A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been published… | |
| Analizada | Media (5.5) | 0.17% | — | Freedesktop LibinputFedoraproject Fedora | 1/4/2026 | 17/6/2026 | A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose… | |
| Modificada | Alta (8.8) | 0.21% | — | Freedesktop LibinputFedoraproject Fedora | 1/4/2026 | 15/7/2026 | A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical… | |
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Sanitize OR Validate This InputAI | 24/3/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Ninguna (0) | 0.52% | — | Leanprover Unicode Input ComponentAI | 16/3/2026 | 17/6/2026 | Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The… | |
| Aplazada | Media (6.7) | 0.18% | — | InputmapperAI | 11/3/2026 | 17/6/2026 | InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a denial of service by copying a large payload into the username field and double-clicking to process it, causing the… | |
| Aplazada | Alta (8.5) | 0.18% | — | Input DirectorAI | 28/1/2026 | 17/6/2026 | Input Director 1.4.3 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Aplazada | Alta (8.5) | 0.21% | — | InputplumberAI | 14/1/2026 | 17/6/2026 | Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 8/3/2025 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. This may make it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (6.5) | 0.32% | — | Beijing Sogou Technology Development CO LTD Sogou Input IOSAI | 27/1/2025 | 17/6/2026 | An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Baidu Input MethodAI | 27/1/2025 | 17/6/2026 | An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link. | |
| Analizada | Media (6.5) | 0.76% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 26/11/2024 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.3) | 0.20% | — | Tychesoftwares Product Input Fields FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Product Input Fields for WooCommerce.This issue affects Product Input Fields for WooCommerce: from n/a through 1.7.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 7/6/2023 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service. |