Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
471 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Zero SpamAI | 25/9/2026 | 25/9/2026 | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all versions up to, and including, 5.7.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.6) | 0.32% | — | PhpipamAI | 25/9/2026 | 30/9/2026 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. | |
| Pendiente de análisis | Crítica (9.6) | 0.38% | — | Fortinet Fortipam Chrome ExtensionAI | 22/9/2026 | 26/9/2026 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack | |
| Aplazada | Media (5.3) | 0.23% | — | Wpamelia AmeliaAI | 17/9/2026 | 18/9/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it… | |
| Aplazada | Media (4.3) | 0.25% | — | Invisible Anti Spam AND CaptchaAI | 17/9/2026 | 18/9/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | SssdAILinux PAMAI | 14/9/2026 | 16/9/2026 | A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a… | |
| Aplazada | Media (5.7) | 0.47% | — | Ocaml OpamAI | 9/9/2026 | 14/9/2026 | In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files. | |
| Pendiente de análisis | Baja (2.7) | 0.50% | — | Fortinet FortiosAIFortinet FortipamAIFortinet FortiproxyAI | 8/9/2026 | 8/9/2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2… | |
| Aplazada | Alta (7.2) | 0.47% | — | Cleantalk Spam Protection Honeypot Anti SpamAI | 5/9/2026 | 8/9/2026 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI | 2/9/2026 | 8/9/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GTI Throws Spam AwayAI | 31/8/2026 | 1/9/2026 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | |
| Aplazada | Media (5.5) | 0.69% | — | Danielpopamd Linkedin-ads-mcpAI | 27/8/2026 | 28/8/2026 | A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed… | |
| Aplazada | Crítica (9.3) | 0.64% | — | PhpipamAI | 24/8/2026 | 24/9/2026 | phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an… | |
| Pendiente de análisis | Alta (8.7) | 0.48% | — | PhpipamAI | 17/8/2026 | 24/9/2026 | phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without… | |
| Aplazada | Media (4.9) | 0.50% | — | Invisible Anti Spam CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via Pattern JSON Keys/Values in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.2) | 0.46% | — | Invisible Anti Spam AND CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (4.9) | 0.58% | — | Invisible Anti Spam AND CaptchaAI | 15/8/2026 | 20/8/2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Maspik Spam BlacklistAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | |
| Pendiente de análisis | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cleantalk Spam ProtectionAICleantalk AntispamAICleantalk FirewallAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| Aplazada | Media (6.1) | 0.10% | — | Samba PAM WinbindAI | 15/7/2026 | 15/7/2026 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this… | |
| Modificada | Media (5.5) | 0.25% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions,… | |
| Modificada | Media (6.6) | 0.67% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all… | |
| Modificada | Media (6.1) | 0.39% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 14/7/2026 | 11/8/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions,… |