Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Limesurvey Community EditionAI | 29/9/2026 | 30/9/2026 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request… | |
| Aplazada | Alta (8.5) | 0.27% | — | Taskview CommunityAI | 24/9/2026 | 24/9/2026 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers… | |
| Aplazada | Media (5.5) | 0.25% | — | Java110 MicrocommunityAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.4) | 0.39% | — | Limesurvey Community EditionAI | 23/9/2026 | 23/9/2026 | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. | |
| Pendiente de análisis | Alta (8.7) | 0.57% | — | Concretecms Community StoreAI | 22/9/2026 | 25/9/2026 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by… | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Concrete Community StoreAI | 18/9/2026 | 28/9/2026 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data. | |
| Aplazada | Crítica (9.3) | 0.64% | — | Uvdesk Community SkeletonAI | 16/9/2026 | 22/9/2026 | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control… | |
| Pendiente de análisis | Alta (8.1) | 0.72% | — | Ansible Community.generalAIMemcachedAIPython-memcachedAI | 9/9/2026 | 9/9/2026 | A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached… | |
| Aplazada | Media (5.3) | 0.40% | — | Fastgpt Community EditionAI | 31/8/2026 | 1/9/2026 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all… | |
| Aplazada | Media (5.1) | 0.40% | — | Limesurvey Community EditionAI | 27/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Jetlinks CommunityAI | 26/8/2026 | 9/9/2026 | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). | |
| Aplazada | Media (4.8) | 0.41% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | |
| Aplazada | Alta (7.4) | 0.46% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects… | |
| Aplazada | Alta (7.2) | 0.24% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5. | |
| Aplazada | Alta (8.4) | 0.26% | — | Limesurvey Community EditionAI | 26/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data… | |
| Aplazada | Alta (7.1) | 0.40% | — | Dradis Community EditionAI | 25/8/2026 | 24/9/2026 | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an… | |
| Aplazada | Alta (8.4) | 1.1% | — | Sakura Editor Development Community Sakura EditorAI | 24/8/2026 | 28/8/2026 | Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | |
| Pendiente de análisis | Alta (7.7) | 0.60% | — | Langchain CommunityAI | 20/8/2026 | 24/9/2026 | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to… | |
| Aplazada | Alta (8.6) | 1.5% | — | Otrs Community EditionAI | 20/8/2026 | 24/9/2026 | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are… | |
| Aplazada | Alta (7.2) | 0.47% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into… | |
| Aplazada | Alta (7.4) | 0.46% | — | Humhub Community EditionAI | 19/8/2026 | 28/8/2026 | HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow. | |
| Aplazada | Alta (8.5) | 0.36% | — | Peepso CommunityAI | 19/8/2026 | 20/8/2026 | Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Trading Community | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. Successful… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Trading Community | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community.… | |
| Pendiente de análisis | Alta (7.3) | 0.17% | — | Dell AppsyncAIDell Metro NodeAIDell UCC EdgeAIDell VxrailAI+5 | 18/8/2026 | 20/8/2026 | Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4… |