Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
400.296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | — | — | — | 1/10/2026 | 1/10/2026 | Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (8.6) | — | — | — | 1/10/2026 | 1/10/2026 | Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (7.1) | — | — | — | 1/10/2026 | 1/10/2026 | Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards. | |
| Aplazada | Alta (7.5) | — | — | — | 1/10/2026 | 1/10/2026 | A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Alta (7.4) | — | — | — | 1/10/2026 | 1/10/2026 | A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Media (5.9) | — | — | — | 1/10/2026 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | |
| Aplazada | Media (5.9) | — | — | — | 1/10/2026 | 1/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | |
| Analizada | Media (5.5) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | |
| Analizada | Media (5.4) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | |
| Analizada | Media (4.3) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | |
| Analizada | Media (6.6) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | |
| Analizada | Alta (8.1) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | |
| En análisis | Media (6.5) | — | — | — | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | |
| Analizada | Media (6.5) | — | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | |
| En análisis | Alta (7.2) | — | — | — | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | |
| En análisis | Baja (2) | — | — | — | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | |
| En análisis | Alta (7.1) | — | — | — | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | |
| Aplazada | Alta (7.2) | — | — | — | 1/10/2026 | 1/10/2026 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.2) | — | — | — | 1/10/2026 | 1/10/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | — | — | — | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | — | — | — | 1/10/2026 | 1/10/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | — | — | — | 1/10/2026 | 1/10/2026 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated… | |
| Aplazada | Alta (7.2) | — | — | — | 1/10/2026 | 1/10/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | — | — | — | 1/10/2026 | 1/10/2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.1) | — | — | — | 1/10/2026 | 1/10/2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… |