Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.28%—Interinfo DreammakerAI4/9/20268/9/2026
DreamMaker, desarrollado por Interinfo, tiene una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) reflejada. Los atacantes remotos autenticados pueden ejecutar código JavaScript arbitrario en el navegador del usuario a través de un sitio web malicioso.
AplazadaAlta (8.7)0.54%—Interinfo DreammakerAI4/9/20268/9/2026
DreamMaker, desarrollado por Interinfo, tiene una vulnerabilidad de inyección SQL. Los atacantes remotos autenticados pueden inyectar comandos SQL arbitrarios para leer, modificar y eliminar el contenido de la base de datos.
Pendiente de análisisAlta (8.5)0.63%—Amazon Sagemaker Python SDKAI1/9/20263/9/2026
El almacenamiento en texto claro de información confidencial en el componente de pipeline de los decoradores @step y @remote en Amazon SageMaker Python SDK anterior a la v3.11.0 y la v2.256.0 podría permitir a un usuario remoto autenticado extraer la clave de firma HMAC de las respuestas de la API DescribePipeline de…
AplazadaMedia (6.4)0.26%—Bootstrapped WP Recipe MakerAI1/9/20261/9/2026
El plugin WP Recipe Maker Premium para WordPress es vulnerable a secuencias de comandos en sitios cruzados (XSS) almacenadas a través del shortcode 'wprm-call-to-action' del plugin en todas las versiones hasta la 10.5.0 incluida, debido a un saneamiento insuficiente de la entrada y a un escape insuficiente de la…
AplazadaAlta (8.3)0.26%—NetmakerAI26/8/202624/9/2026
Netmaker deshabilita la verificación de certificados en la conexión con el servidor de correo configurado. El remitente de pro/email/smtp.go asigna una configuración TLS cuyo campo skip-verify se establece en true de forma incondicional, justo debajo de un comentario que indica que el ajuste debería ser false en…
AplazadaAlta (7.1)0.25%—10web Form MakerAI20/8/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49.
AplazadaMedia (5.3)0.49%—10web Form MakerAI15/8/202620/8/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of…
AplazadaCrítica (9.1)0.56%—Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI13/8/202626/8/2026
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting…
AplazadaCrítica (9.1)0.63%—Html FormhandlerAIPerlAILocale MaketextAI13/8/20268/9/2026
HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the…
AplazadaAlta (8.1)0.39%—10web Form MakerAI12/8/202626/8/2026
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Pendiente de análisisMedia (6.5)0.24%—SssdAIRedhat Insights-coreAIClusterlabs PacemakerAI11/8/202614/8/2026
A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.
AplazadaAlta (7.1)0.25%—Ays-pro Survey MakerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
AplazadaAlta (7.1)0.25%—Code-atlantic Popup MakerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
AnalizadaMedia (4.9)0.49%—Claris Filemaker Server9/7/202610/7/2026
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
AplazadaAlta (7.2)1.2%—Code-atlantic Popup MakerAI9/7/20269/7/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (7.1)0.25%—Ays-pro Survey MakerAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
AplazadaAlta (8.4)1.1%—Gotcha Gotcha Games INC RPG Maker MVAIGotcha Gotcha Games INC RPG Maker MZAI30/6/202630/6/2026
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.
AplazadaMedia (4.9)0.34%—10web Form MakerAI18/6/202618/6/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaMedia (4.9)0.34%—10web Form MakerAI18/6/202618/6/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaAlta (8.8)0.48%—Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI17/6/20266/10/2026
Inyección de objetos PHP para suscriptores en el tema de WordPress Entrepreneur - Booking for Small Businesses versiones menor o igual a 3.1.3.
Pendiente de análisisAlta (8.6)0.56%—Clusterlabs PacemakerAI16/6/202621/8/2026
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in…
AplazadaCrítica (9.3)0.40%—10web Form MakerAI15/6/202617/6/2026
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
AplazadaMedia (6.9)0.39%—Interinfo DreammakerAI29/5/202621/7/2026
DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de salto de ruta, permitiendo a atacantes remotos no autenticados leer nombres de archivos bajo una ruta arbitraria explotando una vulnerabilidad de salto de ruta absoluto.
AplazadaMedia (6.9)0.35%—Interinfo DreammakerAI29/5/202621/7/2026
DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de lectura arbitraria de archivos, permitiendo a atacantes locales privilegiados explotar el salto de ruta relativo para descargar archivos de sistema arbitrarios.
AplazadaAlta (8.7)0.35%—Interinfo DreammakerAI29/5/202621/7/2026
DreamMaker desarrollado por Interinfo tiene una vulnerabilidad de lectura arbitraria de archivos, permitiendo a atacantes locales no autenticados explotar el salto de ruta relativo para descargar archivos arbitrarios del sistema.
Orbitaley — Vulnerabilidades