Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.49% | — | Bluewavelabs CheckmateAI | 3/9/2026 | 10/9/2026 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and… | |
| Aplazada | Alta (8.5) | 0.75% | — | KubevelaAI | 28/8/2026 | 9/9/2026 | KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a… | |
| Aplazada | Alta (7.2) | 0.58% | — | Bluewavelabs CheckmateAI | 27/8/2026 | 1/9/2026 | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint. | |
| Aplazada | Alta (7.5) | 0.48% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete… | |
| Aplazada | Media (4.9) | 0.59% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue… | |
| Aplazada | Alta (7.5) | 0.62% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through… | |
| Aplazada | Media (5.3) | 0.42% | — | Bluewavelabs CheckmateAI | 10/8/2026 | 28/8/2026 | A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered… | |
| Aplazada | Alta (8.2) | 0.33% | — | Bluewavelabs CheckmateAI | 6/8/2026 | 26/8/2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the… | |
| Analizada | Alta (8.1) | 0.36% | — | Bluewavelabs Checkmate | 20/3/2026 | 17/6/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to… | |
| Analizada | Media (5.3) | 0.41% | — | Bluewavelabs Checkmate | 7/3/2026 | 17/6/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url endpoint. The… | |
| Aplazada | Alta (8.1) | 0.42% | — | Axiomthemes MarvelandAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Marveland marveland allows PHP Local File Inclusion.This issue affects Marveland: from n/a through <= 1.3.0. | |
| Analizada | Baja (3.3) | 0.21% | — | Maevelander Sticky Side Buttons | 3/9/2025 | 17/6/2026 | The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Crítica (9.8) | 0.46% | — | RevelacodeAIMongodb AtlasAI | 28/7/2025 | 17/6/2026 | RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to… | |
| Aplazada | Media (5) | 0.34% | — | Bluewavelabs CheckmateAI | 15/5/2025 | 17/6/2026 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint. | |
| Aplazada | Alta (8.8) | 0.50% | — | Bluewavelabs CheckmateAI | 10/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter. | |
| Aplazada | Alta (8.1) | 0.50% | — | Bluewavelabs CheckmateAI | 4/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. | |
| Aplazada | Alta (8.5) | 0.27% | — | Go-vela VelaAI | 10/3/2025 | 17/6/2026 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a specific set of headers and body data, an attacker could transfer ownership of a repository and its repo level secrets to a separate… | |
| Aplazada | Alta (7.1) | 0.39% | — | Maevelander Rezdy ReloadedAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maeve Lander Rezdy Reloaded reloaded-rezdy allows Stored XSS.This issue affects Rezdy Reloaded: from n/a through <= 1.0.1. | |
| Aplazada | Baja (3.1) | 0.34% | — | Clevelandwebdeveloper SpacerAI | 7/1/2025 | 17/6/2026 | The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view limited setting… | |
| Aplazada | Alta (7.1) | 0.15% | — | Maevelander Paypal ResponderAI | 1/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2. | |
| Analizada | Media (6.5) | 0.72% | — | Go-vela Worker | 12/3/2024 | 17/6/2026 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields like `parameters`, `image` and `entrypoint` to inject secrets into a plugin/image and — by using common substitution string manipulation —… | |
| Modificada | Media (6.8) | 0.73% | — | Alpha-innotec Heat Pumps FirmwareNovelan Heat Pumps Firmware | 30/1/2024 | 17/6/2026 | An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file. | |
| Modificada | Media (5.4) | 0.38% | — | Maevelander WP Catalogue | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catalogue allows Stored XSS.This issue affects WP Catalogue: from n/a through 1.7.6. | |
| Modificada | Media (4.7) | 0.41% | — | Travelable Trek Management Solution Project Travelable Trek Management Solution | 24/7/2023 | 17/6/2026 | A vulnerability was found in Travelmate Travelable Trek Management Solution 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Box Handler. The manipulation of the argument comment leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (4.8) | 0.50% | — | Clevelandwebdeveloper Spacer | 21/11/2022 | 17/6/2026 | The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). |