Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21.577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | 0.26% | — | Strong TestimonialsAI | 3/10/2026 | 3/10/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Recibida | Media (5.3) | 0.29% | — | Canonical Postgresql OperatorAI | 2/10/2026 | 3/10/2026 | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which… | |
| Recibida | Media (5.3) | 0.27% | — | Canonical MaasAI | 2/10/2026 | 3/10/2026 | An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker… | |
| Aplazada | Alta (7.2) | 0.27% | — | Limesurvey Community EditionAI | 2/10/2026 | 2/10/2026 | An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript… | |
| Aplazada | Media (4.7) | 0.17% | — | Mehul Gohil Aculect AI CompanionAI | 2/10/2026 | 2/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| Aplazada | Alta (7.2) | 0.31% | — | Download MonitorAI | 2/10/2026 | 2/10/2026 | The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Aplazada | Alta (7.2) | 0.29% | — | Ninjaforms Ninja FormsAI | 2/10/2026 | 3/10/2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | Samsung ManagedprovisioningAI | 2/10/2026 | 2/10/2026 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | |
| Aplazada | Sin puntuar | 0.32% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution | |
| Aplazada | Sin puntuar | 0.14% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | |
| Aplazada | Media (6.5) | 0.18% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | |
| Aplazada | Sin puntuar | 0.14% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Aplazada | Sin puntuar | 0.14% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Aplazada | Sin puntuar | 0.15% | — | Infiniflow RagflowAI | 1/10/2026 | 2/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. | |
| Aplazada | Media (5.1) | 0.16% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory… | |
| Aplazada | Alta (7) | 0.34% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation… | |
| Aplazada | Alta (8.6) | 0.59% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Aplazada | Media (5.5) | 0.54% | — | Getgrav Dom-sanitizerAI | 1/10/2026 | 1/10/2026 | A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2) | 0.36% | — | Rhukster DOM SanitizerAI | 1/10/2026 | 1/10/2026 | A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be… | |
| Aplazada | Media (5.3) | 0.18% | — | Geminilabs Site ReviewsAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | |
| Aplazada | Media (5.9) | 0.40% | — | Genian NAC ZtnaAI | 1/10/2026 | 1/10/2026 | A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | |
| Aplazada | Alta (8.4) | 1.9% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely | |
| Aplazada | Alta (7.5) | 0.23% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration |