Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

312 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)——Limesurvey Community EditionAI2/10/20262/10/2026
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript…
AplazadaAlta (7.1)0.24%—Limesurvey Community EditionAI29/9/202630/9/2026
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request…
AplazadaAlta (8.5)0.27%—Taskview CommunityAI24/9/202624/9/2026
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers…
AplazadaMedia (5.5)0.25%—Java110 MicrocommunityAI24/9/202624/9/2026
A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is…
AplazadaAlta (7.4)0.39%—Limesurvey Community EditionAI23/9/202623/9/2026
LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.
Pendiente de análisisAlta (8.7)0.57%—Concretecms Community StoreAI22/9/202625/9/2026
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by…
Pendiente de análisisAlta (8.6)0.37%—Concrete Community StoreAI18/9/202628/9/2026
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
AplazadaCrítica (9.3)0.64%—Uvdesk Community SkeletonAI16/9/202622/9/2026
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control…
Pendiente de análisisAlta (8.1)0.72%—Ansible Community.generalAIMemcachedAIPython-memcachedAI9/9/20269/9/2026
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached…
AplazadaMedia (5.3)0.40%—Fastgpt Community EditionAI31/8/20261/9/2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all…
AplazadaMedia (5.1)0.40%—Limesurvey Community EditionAI27/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without…
AplazadaCrítica (9.1)0.40%—Jetlinks CommunityAI26/8/20269/9/2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
AplazadaMedia (4.8)0.41%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (7.4)0.46%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects…
AplazadaAlta (7.2)0.24%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (8.4)0.26%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data…
AplazadaAlta (7.1)0.40%—Dradis Community EditionAI25/8/202624/9/2026
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an…
AplazadaAlta (8.4)1.1%—Sakura Editor Development Community Sakura EditorAI24/8/202628/8/2026
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Pendiente de análisisAlta (7.7)0.60%—Langchain CommunityAI20/8/202624/9/2026
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to…
AplazadaAlta (8.6)1.5%—Otrs Community EditionAI20/8/202624/9/2026
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are…
AplazadaAlta (7.2)0.47%—Humhub Community EditionAI19/8/202628/8/2026
HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into…
AplazadaAlta (7.4)0.46%—Humhub Community EditionAI19/8/202628/8/2026
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
AplazadaAlta (8.5)0.36%—Peepso CommunityAI19/8/202620/8/2026
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
AnalizadaAlta (8.1)0.39%—Oracle Trading Community18/8/202631/8/2026
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. Successful…
AnalizadaAlta (8.6)0.41%—Oracle Trading Community18/8/202631/8/2026
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community.…