Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.36% | — | Webo MCPAI | 30/9/2026 | 30/9/2026 | Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. | |
| Aplazada | Media (6.1) | 0.42% | — | Pylonsproject WebobAI | 20/8/2026 | 18/9/2026 | WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a… | |
| Analizada | Media (6.1) | 0.27% | — | Pylonsproject Webob | 22/6/2026 | 26/6/2026 | WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage… | |
| Analizada | Alta (8.8) | 0.49% | — | Weborange Bargain Product VM3 | 19/6/2026 | 19/8/2026 | Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract… | |
| Analizada | Alta (8.8) | 0.49% | — | Weborange Price Alert | 19/6/2026 | 19/8/2026 | Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to… | |
| Modificada | Media (6.9) | 0.73% | — | Webonyx Graphql-php | 17/4/2026 | 14/9/2026 | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during… | |
| Aplazada | Media (6.5) | 0.26% | — | Awethemes AwebookingAI | 5/1/2026 | 30/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embedded Sensitive Data.This issue affects AweBooking: from n/a through <= 3.2.26. | |
| Aplazada | Alta (7.1) | 0.25% | — | Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a… | |
| Aplazada | Alta (7.1) | 0.39% | — | Editionskezzal Cobwebo URLAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in editionskezzal Cobwebo URL Plugin cobwebo-url allows Reflected XSS.This issue affects Cobwebo URL Plugin: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.31% | — | Weboccult Technologies PVT LTD WOT Elementor WidgetsAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Wot Elementor Widgets wot-elementor-widgets allows DOM-Based XSS.This issue affects Wot Elementor Widgets: from n/a through <= 1.0.1. | |
| Analizada | Media (5.4) | 0.29% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser. | |
| Analizada | Crítica (9.8) | 0.47% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Media (6.1) | 0.33% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques. | |
| Analizada | Crítica (9.8) | 0.83% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
| Analizada | Alta (8.8) | 0.77% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
| Analizada | Crítica (9.8) | 0.56% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Crítica (9.1) | 0.63% | — | WeborfAI | 9/10/2024 | 17/6/2026 | cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused. | |
| Analizada | Crítica (9.8) | 0.64% | — | Medialibs Webo-facto | 20/9/2024 | 17/6/2026 | The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains… | |
| Analizada | Media (6.1) | 0.57% | — | Pylonsproject Webob | 14/8/2024 | 17/6/2026 | WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's urlparse, and joining it to the base URL. `urlparse` however treats a `//` at the start of a string as… | |
| Analizada | Alta (7.2) | 3.9% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability. | |
| Analizada | Alta (7.2) | 6.4% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this… | |
| Analizada | Alta (7.2) | 4.7% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.… | |
| Analizada | Crítica (9.8) | 1.1% | — | LG Webos | 9/4/2024 | 17/6/2026 | A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA… | |
| Analizada | Alta (8.8) | 0.80% | — | LG Webos Signage | 26/2/2024 | 17/6/2026 | This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. | |
| Analizada | Crítica (9.8) | 0.92% | — | LG Webos Signage | 26/2/2024 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage. |