Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2721▲ 17 respecto a la semana anterior
Críticas / altas1459▲ 351 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)72▼ 458 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.76%—WavelogAI17/9/202624/9/2026
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in…
Pendiente de análisisAlta (8.4)0.10%—Waves CentralAI8/9/202614/9/2026
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier…
AplazadaAlta (7.1)0.49%—Bluewavelabs CheckmateAI3/9/202610/9/2026
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and…
AplazadaMedia (6.4)0.19%—Easy Waveform PlayerAI2/9/20263/9/2026
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaAlta (7.6)0.34%—WavesuiteAI31/8/20263/9/2026
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
AplazadaAlta (7.2)0.58%—Bluewavelabs CheckmateAI27/8/20261/9/2026
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
AplazadaAlta (7.5)0.48%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete…
AplazadaMedia (4.9)0.59%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue…
AplazadaAlta (7.5)0.62%—Bluewavelabs CheckmateAI21/8/202618/9/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through…
AplazadaMedia (6.5)0.42%—Flutterwave WoocommerceAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
AplazadaMedia (5.3)0.42%—Bluewavelabs CheckmateAI10/8/202628/8/2026
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered…
AplazadaAlta (8.2)0.33%—Bluewavelabs CheckmateAI6/8/202626/8/2026
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the…
AnalizadaMedia (6.1)0.34%—Carrierwave Project Carrierwave17/6/202618/6/2026
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not match the content types it is intended to block. In…
AplazadaAlta (8.1)0.32%—Waves CentralAI9/6/202623/7/2026
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker…
AplazadaAlta (7.8)0.15%—Waves CentralAI9/6/202623/7/2026
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the DYLD_INSERT_LIBRARIES environment variable…
Pendiente de análisisAlta (8.4)0.16%—Markdown Preview EnhancedAICrossnoteAIWavedromAIMicrosoft VS CodeAI5/6/202623/7/2026
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the…
AplazadaAlta (8.6)0.64%—Markdown Preview EnhancedAIWavedromAI5/6/202617/6/2026
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll()/eva() helpers) -…
AplazadaAlta (8.1)0.56%—Select-themes WaverideAI2/6/202622/7/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4.
AnalizadaCrítica (10)0.31%—Acer Wave 7 Firmware29/5/202621/7/2026
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
AnalizadaCrítica (10)0.61%—Acer Wave 7 Firmware29/5/202621/7/2026
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
AplazadaMedia (5.5)0.64%—Aiwaves-cn AgentsAIAiwaves-cn Cheshire CAT CoreAI11/5/202617/6/2026
A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/cat/looking_glass/stray_cat.py of the component cheshire_cat_core. This manipulation causes resource consumption. Remote…
AnalizadaMedia (4.9)0.21%—Remnawave Backend8/4/202624/7/2026
Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register more devices than expected, allowing them to resell subscriptions and consume…
AnalizadaAlta (8.1)0.36%—Bluewavelabs Checkmate20/3/202617/6/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to…
AnalizadaMedia (5.3)0.41%—Bluewavelabs Checkmate7/3/202617/6/2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url endpoint. The…
AplazadaMedia (6.4)0.25%—Wavesurfer WPAI6/2/202617/6/2026
The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on the 'src' attribute. This makes it possible for authenticated attackers, with Contributor-level…