Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
2100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Leap13 Premium Addons FOR ElementorAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Media (5.3) | 0.65% | — | Input LeapAI | 25/9/2026 | 30/9/2026 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message. | |
| Aplazada | Media (6.5) | 0.17% | — | Leap13 Premium Addons FOR ElementorAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | |
| Aplazada | Alta (8.8) | 1.8% | — | Tuleap Enterprise EditionAI | 21/9/2026 | 21/9/2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Redhat Leapp-repositoryAIOracle MysqlAI | 15/9/2026 | 16/9/2026 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that… | |
| Pendiente de análisis | Alta (7.7) | 0.20% | — | Tuleap Enterprise EditionAI | 25/8/2026 | 28/8/2026 | A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import. | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Ansible-collection-redhat-leappAI | 30/7/2026 | 3/8/2026 | A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive… | |
| Pendiente de análisis | Media (6.2) | 0.38% | — | Ansible-collection-redhat-leappAI | 30/7/2026 | 3/8/2026 | A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Tuleap Enterprise EditionAI | 13/7/2026 | 13/7/2026 | An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization. | |
| Aplazada | Media (4.9) | 0.29% | — | Leap13 Premium Addons FOR ElementorAI | 11/7/2026 | 14/7/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Oceanicsoft ValeappAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.5) | 0.67% | — | Simplyscheduleappointments Appointment Booking CalendarAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (5.4) | 0.24% | — | Leap13 Premium Addons FOR ElementorAI | 2/5/2026 | 17/6/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Pendiente de análisis | Alta (8.4) | 0.20% | — | AleappAI | 8/4/2026 | 24/7/2026 | ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a database directly as the output filename, allowing arbitrary file writes outside the report output directory. An attacker… | |
| Analizada | Media (4.6) | 0.16% | — | Enalean Tuleap | 2/2/2026 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is… | |
| Aplazada | Media (5.4) | 0.24% | — | Leap13 Premium Addons FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.63. | |
| Modificada | Media (5.3) | 0.34% | — | Leap13 Premium Addons FOR Elementor | 24/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53. | |
| Modificada | Media (4.3) | 0.16% | — | Leap13 Premium Addons FOR Elementor | 23/12/2025 | 17/6/2026 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary Elementor templates… | |
| Modificada | Media (5.3) | 0.76% | — | Leap13 Premium Addons FOR Elementor | 23/12/2025 | 17/6/2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.3) | 0.16% | — | Enalean Tuleap | 9/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap Enterprise Edition versions prior to 17.0-4 and 16.13-9 are mission CSRF protections in its tracker field dependencies, allowing attackers to… | |
| Analizada | Media (4.3) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This… | |
| Analizada | Media (5.4) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. Attackers have… | |
| Analizada | Media (4.3) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in… | |
| Analizada | Media (6.5) | 0.28% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This… |