Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.73% | — | Silverstripe UserformsAISilverstripe CMSAI | 27/8/2026 | 9/9/2026 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to… | |
| Aplazada | Media (6.5) | 0.12% | — | Hsiaoming JoserfcAI | 24/8/2026 | 9/9/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended… | |
| Aplazada | Baja (2.3) | 0.14% | — | Hsiaoming JoserfcAI | 29/7/2026 | 30/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts JWTs with trailing padding (==) which are not conforming to the JOSE specifications. This leads to malleability of the JWTs when consumed by joserfc.… | |
| Aplazada | Alta (8.7) | 0.19% | — | Hsiaoming JoserfcAI | 17/7/2026 | 23/7/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and… | |
| Aplazada | Media (5.3) | 0.27% | — | Hsiaoming JoserfcAI | 17/6/2026 | 23/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion. The normal JWS… | |
| Analizada | Alta (7.5) | 0.35% | — | Hsiaoming Joserfc | 3/3/2026 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library decrypts a JSON Web… | |
| Analizada | Crítica (9.2) | 0.41% | — | Hsiaoming Joserfc | 18/11/2025 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Python logging to… | |
| Modificada | Media (6.1) | 0.40% | — | Monsterinsights Userfeedback | 12/7/2024 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (6.1) | 0.43% | — | Monsterinsights Userfeedback | 22/2/2024 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Media (6.1) | 0.35% | — | Monsterinsights Userfeedback | 27/10/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions. | |
| Analizada | Media (6.1) | 0.56% | — | Monsterinsights Userfeedback | 29/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | |
| Modificada | Alta (8.8) | 1.5% | — | Userfrosting | 3/1/2022 | 17/6/2026 | In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account. | |
| Modificada | Media (5.4) | 0.27% | — | Userfriendlymedia Mills-hazel Property Mgmt | 21/10/2014 | 17/6/2026 | The Mills-Hazel Property Mgmt (aka com.appexpress.millshazelpropertymanagement) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Userfriendlymedia Joe's Lawn Service | 19/10/2014 | 17/6/2026 | The Joe's Lawn Service (aka com.appexpress.joeslawnservice) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 3.1% | — | Apache SubversionCanonical Ubuntu LinuxSerf Project Serf | 19/8/2014 | 17/6/2026 | The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary… | |
| Modificada | Alta (7.5) | 1.3% | — | Jens Vagelpohl Zope-ldapuserfolder | 20/8/2010 | 16/6/2026 | The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges. | |
| Modificada | Alta (7.2) | 1.2% | — | Hans Reiser ReiserfsSuse Linux | 26/3/2001 | 16/6/2026 | Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name. | |
| Modificada | Alta (10) | 1.6% | — | LaserficheAINovell NetwareAI | 1/1/1999 | 16/6/2026 | NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging. |