Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.25% | — | CMP Coming Soon MaintenanceAI | 2/10/2026 | 2/10/2026 | The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request… | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Aplazada | Alta (8.7) | 0.52% | — | KnowstreamingAI | 16/9/2026 | 24/9/2026 | KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization. | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Live555 Streaming MediaAI | 9/9/2026 | 14/9/2026 | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Xbox Gaming Services | 8/9/2026 | 14/9/2026 | Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (5.4) | 0.31% | — | FlamingoAI | 7/9/2026 | 8/9/2026 | The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to enumerate… | |
| Aplazada | Crítica (9.8) | 1.4% | — | HummingbirdAI | 5/9/2026 | 8/9/2026 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to… | |
| Aplazada | Alta (7.2) | 0.37% | — | HummingbirdAI | 4/9/2026 | 8/9/2026 | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |
| Aplazada | Media (6.9) | 0.32% | — | WyomingAI | 1/9/2026 | 8/9/2026 | Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected… | |
| Aplazada | Baja (2.1) | 0.38% | — | Caoqianming Django-vue-adminAI | 31/8/2026 | 1/9/2026 | A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (6.5) | 0.12% | — | Hsiaoming JoserfcAI | 24/8/2026 | 9/9/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended… | |
| Aplazada | Alta (8.2) | 0.10% | — | HP Omen Gaming HUBAI | 21/8/2026 | 31/8/2026 | A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester PET Grooming Management SoftwareAI | 17/8/2026 | 20/8/2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Alta (7.2) | 0.59% | — | Frostming UnearthAI | 10/8/2026 | 24/9/2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal… | |
| Aplazada | Media (5.5) | 0.48% | — | Mingsoft McmsAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.48% | — | Mingsoft McmsAI | 9/8/2026 | 13/8/2026 | A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.41% | — | Mingsoft McmsAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Alta (8.4) | 0.19% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is… | |
| Aplazada | Alta (8.4) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe… | |
| Aplazada | Media (6.8) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets.… | |
| Aplazada | Baja (2.3) | 0.14% | — | Hsiaoming JoserfcAI | 29/7/2026 | 30/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts JWTs with trailing padding (==) which are not conforming to the JOSE specifications. This leads to malleability of the JWTs when consumed by joserfc.… | |
| Aplazada | Alta (7.1) | 0.16% | — | Linux-gaming PortprotonqtAIGnome NetworkmanagerAI | 23/7/2026 | 23/7/2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. | |
| Aplazada | Alta (8.7) | 0.19% | — | Hsiaoming JoserfcAI | 17/7/2026 | 23/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Aplazada | Baja (2.1) | 0.46% | — | Kofrasa MingoAI | 14/7/2026 | 14/7/2026 | A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the argument Set can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. Upgrading to… |