Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

21.577 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)0.26%—Strong TestimonialsAI3/10/20263/10/2026
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
RecibidaMedia (5.3)0.29%—Canonical Postgresql OperatorAI2/10/20263/10/2026
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which…
RecibidaMedia (5.3)0.27%—Canonical MaasAI2/10/20263/10/2026
An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker…
AplazadaAlta (7.2)0.27%—Limesurvey Community EditionAI2/10/20262/10/2026
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript…
AplazadaMedia (4.7)0.17%—Mehul Gohil Aculect AI CompanionAI2/10/20262/10/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1.
AplazadaMedia (6.5)0.20%—Avez Electronics Learning Management SystemAI2/10/20262/10/2026
Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18.
AplazadaAlta (7.2)0.31%—Download MonitorAI2/10/20262/10/2026
The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaAlta (7.2)0.29%—Ninjaforms Ninja FormsAI2/10/20263/10/2026
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Pendiente de análisisMedia (6.9)0.10%—Samsung ManagedprovisioningAI2/10/20262/10/2026
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
AplazadaSin puntuar0.32%—Infiniflow RagflowAI1/10/20262/10/2026
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
AplazadaSin puntuar0.14%—Infiniflow RagflowAI1/10/20262/10/2026
infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
AplazadaMedia (6.5)0.18%—Infiniflow RagflowAI1/10/20262/10/2026
Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
AplazadaSin puntuar0.14%—Infiniflow RagflowAI1/10/20262/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaSin puntuar0.14%—Infiniflow RagflowAI1/10/20262/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaSin puntuar0.15%—Infiniflow RagflowAI1/10/20262/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.
AplazadaMedia (5.1)0.16%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory…
AplazadaAlta (7)0.34%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation…
AplazadaAlta (8.6)0.59%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by…
AplazadaMedia (5.5)0.54%—Getgrav Dom-sanitizerAI1/10/20261/10/2026
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaBaja (2)0.36%—Rhukster DOM SanitizerAI1/10/20261/10/2026
A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be…
AplazadaMedia (5.3)0.18%—Geminilabs Site ReviewsAI1/10/20261/10/2026
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.
AplazadaMedia (5.9)0.40%—Genian NAC ZtnaAI1/10/20261/10/2026
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
AplazadaAlta (8.4)1.9%—Genian SSL PNSAI1/10/20261/10/2026
An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely
AplazadaAlta (7.5)0.23%—Genian SSL PNSAI1/10/20261/10/2026
An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration