Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.42%—PuppyfwAI17/9/202618/9/2026
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their…
Pendiente de análisisCrítica (9.8)0.45%—Transloadit UppyAI14/4/202617/6/2026
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
AplazadaMedia (5.3)0.36%—Wpguppy ONE TO ONE User ChatAI14/2/202617/6/2026
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view…
AplazadaAlta (8.2)0.31%—Amenotech Private Limited WpguppyAIAmenotech Private Limited Wpguppy LiteAI22/10/202517/6/2026
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4.
AplazadaAlta (8.5)0.39%—Amentotech WP GuppyAI9/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy wp-guppy allows SQL Injection.This issue affects WP Guppy: from n/a through <= 4.3.3.
AplazadaAlta (8.5)0.49%—Amentotech Private Limited Wpguppy LiteAI27/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQL Injection.This issue affects WPGuppy: from n/a through <= 1.1.3.
AplazadaMedia (6.5)0.40%—Amentotech WpguppyAI3/2/202517/6/2026
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaAlta (8.8)0.41%—Amentotech Private Limited WpguppyAIAmentotech Private Limited Wpguppy LiteAI7/1/202517/6/2026
Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaCrítica (9.8)0.51%—Amenotech Private Limited WpguppyAI7/1/202517/6/2026
Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0.
ModificadaCrítica (9.8)2.1%—Freeguppy Guppy17/5/202317/6/2026
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
ModificadaMedia (6.1)0.60%—Puppycms12/10/202217/6/2026
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is…
ModificadaAlta (7.5)1.00%—Transloadit Uppy3/3/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
ModificadaCrítica (9.8)1.2%—Transloadit Uppy4/1/202217/6/2026
uppy is vulnerable to Server-Side Request Forgery (SSRF)
ModificadaMedia (6.5)2.8%—Wp-guppy WP Guppy27/12/202117/6/2026
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user
ModificadaCrítica (9.8)1.5%—Puppycms6/5/202117/6/2026
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
ModificadaAlta (7.5)0.78%—Puppycms6/5/202117/6/2026
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
ModificadaMedia (6.5)0.44%—Puppycms6/5/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
ModificadaAlta (7.5)1.2%—Transloadit Uppy20/7/202017/6/2026
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
ModificadaCrítica (9.8)1.3%—Uppy20/3/202017/6/2026
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
ModificadaMedia (6.1)0.87%—Puppycms25/8/201817/6/2026
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.
ModificadaMedia (5.4)0.27%—Starluxstudios Puppy Slots9/9/201417/6/2026
The Puppy Slots (aka air.com.starluxstudios.PuppySlotsFree) application 3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)2.2%—Guppy6/2/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.
ModificadaAlta (7.5)2.0%—Freeguppy Guppy6/5/201016/6/2026
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.
ModificadaAlta (7.5)2.3%—Guppy6/11/200716/6/2026
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin parameter to index.php. NOTE: this can be leveraged for remote file inclusion by including inc/boxleft.inc and specifying a URL in the xposbox[L][]…
ModificadaAlta (7.5)3.0%—Guppy6/11/200716/6/2026
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. NOTE: this can be leveraged to bypass authentication and upload arbitrary files by including admin/inc/upload.inc and…