Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
292.954 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | — | — | Wpmanageninja Fluent Forms PROAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | |
| Recibida | Media (6.9) | — | — | Zabbix ServerAIZabbix ProxyAI | 5/10/2026 | 5/10/2026 | Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity. | |
| Recibida | Baja (2.3) | — | — | Zabbix ServerAIZabbix ProxyAI | 5/10/2026 | 5/10/2026 | The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database. | |
| Recibida | Media (6.9) | — | — | Zabbix ServerAI | 5/10/2026 | 5/10/2026 | The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | |
| Recibida | Media (4.3) | — | — | Deepak Anand WP Dummy Content GeneratorAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. | |
| Recibida | Baja (2.1) | — | — | Feelec-yishu Feelcrm-osAI | 5/10/2026 | 5/10/2026 | A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The… | |
| Recibida | Media (5.5) | — | — | Feelec-yishu Feelcrm-osAI | 5/10/2026 | 5/10/2026 | A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the… | |
| Recibida | Baja (2) | — | — | Feelec-yishu Feelcrm-osAI | 5/10/2026 | 5/10/2026 | A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site… | |
| Recibida | Media (6.6) | — | — | QT FOR McusAI | 5/10/2026 | 5/10/2026 | In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the… | |
| Recibida | Baja (2.1) | — | — | Feelec-yishu Feelcrm-osAI | 5/10/2026 | 5/10/2026 | A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed… | |
| Recibida | Baja (2.1) | — | — | Feelec-yishu Feelcrm-osAI | 5/10/2026 | 5/10/2026 | A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely.… | |
| Recibida | Media (5.3) | — | — | Villatheme CurcyAI | 5/10/2026 | 5/10/2026 | Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | |
| Recibida | Media (5.4) | — | — | Brainstormforce Astra SitesAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Recibida | Alta (7.8) | — | — | Zephyr RtosAI | 5/10/2026 | 5/10/2026 | The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data… | |
| Recibida | Alta (8.4) | — | — | NXP ZephyrAI | 5/10/2026 | 5/10/2026 | The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the… | |
| Aplazada | Media (5.1) | — | — | ShaarliAI | 5/10/2026 | 5/10/2026 | A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The… | |
| Recibida | Baja (2.1) | — | — | Itsourcecode Online Admission SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Recibida | Media (5.5) | — | — | Itsourcecode Online Admission SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Recibida | Media (5.3) | — | — | VgmstreamAI | 5/10/2026 | 5/10/2026 | A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named… | |
| Recibida | Media (6.5) | — | — | Nikki Blight QR RedirectorAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5. | |
| Recibida | Media (5.3) | — | — | Pixelite Events ManagerAI | 5/10/2026 | 5/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | |
| Recibida | Media (6.5) | — | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/10/2026 | 5/10/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Recibida | Media (4.3) | — | — | Brandtoss WP Admin AuditAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17. | |
| Recibida | Media (6.5) | — | — | Implecode Ecommerce Product CatalogAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | |
| Recibida | Media (5.3) | — | — | Wpmailster WP MailsterAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. |