Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.33% | — | Loops AND LogicAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Loops AND LogicAI | 9/9/2026 | 9/9/2026 | The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options. | |
| Aplazada | Media (6.5) | 0.29% | — | Tangible Loops AND LogicAI | 28/8/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic. | |
| Analizada | Media (4.3) | 0.22% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting. | |
| Analizada | Media (5.4) | 0.20% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. | |
| Analizada | Media (4.6) | 0.21% | — | Hcltech Devops Loop | 17/7/2026 | 13/8/2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. | |
| Aplazada | Media (6.5) | 0.24% | — | Tangible Loops AND LogicAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3. | |
| Aplazada | Baja (2.1) | 0.37% | — | Klosk AdloopAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the argument final_url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Devops AutomationIBM Devops Loop | 30/6/2026 | 30/9/2026 | IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Crítica (9.8) | 6.1% | — | Fohrloop Dash-uploaderAI | 8/5/2026 | 17/6/2026 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components. | |
| Modificada | Alta (7.5) | 2.8% | — | Fohrloop Dash-uploader | 8/5/2026 | 17/6/2026 | Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled upload parameters (e.g. flowTotalChunks) and does not enforce the documented… | |
| Aplazada | Alta (7.5) | 0.38% | — | Loopus WP Cost Estimation AND Payment Forms BuilderAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Cost Estimation & Payment Forms Builder WP_Estimation_Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through < 10.3.0. | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9.3) | 0.42% | — | Loopus WP Attractive Donations SystemAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from… | |
| Aplazada | Media (6.4) | 0.20% | — | WikiloopsAI | 7/2/2026 | 17/6/2026 | The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.26% | — | Loopus WP Virtual AssistantAI | 8/1/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Stored XSS.This issue affects WP Virtual Assistant: from n/a through <= 3.1. | |
| Aplazada | Alta (7.5) | 0.43% | — | Loopus WP Attractive Donations SystemAI | 8/1/2026 | 30/9/2026 | Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Aplazada | Media (5.3) | 0.27% | — | Xforwoocommerce Product Loops FOR WoocommerceAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce product-loops allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Loops for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (4.3) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Cross Site Request Forgery.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Aplazada | Alta (8.1) | 0.19% | — | HCL Devops LoopAI | 5/11/2025 | 17/6/2026 | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive… | |
| Aplazada | Media (5.3) | 0.27% | — | Loopus WP Virtual AssistantAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-easy-stripe-paypal-donations allows Stored XSS.This issue affects WP Attractive Donations System: from n/a through < 1.29. | |
| Aplazada | Media (5.3) | 0.32% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. |