Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.14% | — | Activecampaign GeneralAI | 9/9/2026 | 14/9/2026 | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Activecampaign GeneralAI | 26/8/2026 | 28/8/2026 | A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied… | |
| Analizada | Crítica (9.8) | 0.56% | — | Alternativecommerce | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17. | |
| Aplazada | Alta (7.1) | 0.25% | — | NativechurchAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | IEI Integration Corp IvecAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerability to create directories in unintended system paths. | |
| Aplazada | Alta (7.2) | 0.40% | — | IEI Integration Corp Ivec Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories, resulting in data destruction or service disruption. | |
| Aplazada | Alta (8.6) | 0.95% | — | IEI Integration Corp Ivec Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device. | |
| Aplazada | Media (6.9) | 0.41% | — | IEI Integration Corp Ivec-iei Virtualization Edge ComputerAI | 12/6/2026 | 17/6/2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the intended directory scope. | |
| Aplazada | Alta (8.8) | 0.38% | — | LivecodeAI | 25/2/2026 | 17/6/2026 | LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitHub Actions workflow is vulnerable to JavaScript injection. The title of the Pull Request associated with the triggering issue comment is interpolated directly into a… | |
| Aplazada | Media (6.4) | 0.24% | — | InteractivecalculatorAI | 18/2/2026 | 17/6/2026 | The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interactivecalculator' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.21% | — | Givecloud Donation Forms WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9. | |
| Modificada | Media (6.5) | 0.20% | — | Jenkins Nouvola Divecloud | 9/7/2025 | 17/6/2026 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (6.5) | 0.15% | — | Jenkins Nouvola Divecloud | 9/7/2025 | 17/6/2026 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Media (5.9) | 0.40% | — | Activecampaign-subscription-formsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign activecampaign-subscription-forms allows Stored XSS.This issue affects ActiveCampaign: from n/a through <= 8.1.16. | |
| Aplazada | Media (5.4) | 0.46% | — | Pravin Durugkar User Sync ActivecampaignAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign registered-user-sync-activecampaign allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Sync ActiveCampaign: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.34% | — | Popup Mailchimp Getresponse AND Activecampaign IntergrationsAI | 7/1/2025 | 17/6/2026 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'upc_delete_db_data' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to delete the… | |
| Aplazada | Media (6.5) | 0.52% | — | LivechatAI | 12/7/2024 | 17/6/2026 | Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory. | |
| Aplazada | Crítica (10) | 0.61% | — | Livechatpro Module Live Chat PROAI | 19/6/2024 | 17/6/2026 | In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file. | |
| Modificada | Crítica (9.8) | 0.35% | — | Activecampaign | 15/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14. | |
| Modificada | Alta (7.5) | 1.2% | — | Liveconfig | 2/2/2024 | 17/6/2026 | Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint. | |
| Modificada | Alta (8.8) | 0.27% | — | Livechat | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15. | |
| Modificada | Media (5.4) | 0.46% | — | Activecampaign | 15/5/2023 | 17/6/2026 | The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.39% | — | Wp-olivecart Project Wp-olivecart | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Olive Design WP-OliveCart plugin <= 1.1.3 versions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Adobe Livecycle ES4 | 6/4/2023 | 17/6/2026 | A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. Adobe LiveCycle ES4 version 11.0.1 and later may be vulnerable if the… |