Explotadas, aún no en el catálogo de CISA
245 fallos explotados y aún no oficiales
Estas vulnerabilidades tienen pruebas públicas de explotación pero todavía no están en el catálogo de CISA. No traen un plazo legal: traen pruebas. Cuando CISA llega, lo hace una mediana de 20 días después.
- CVE-2026-85520no está en el catálogo de CISA
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the la
Fuentes: cve.org
- CVE-2025-62023Crítica9.0no está en el catálogo de CISA
s2member · s2member
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.
Fuentes: patchstack.com
- CVE-2023-54400no está en el catálogo de CISA
Fumasoft · Fumeng Cloud
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniqu
Fuentes: cve.org
- CVE-2018-8033vista por sensoresno está en el catálogo de CISA
Apache · OFBiz
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMo
Fuentes: dashboard.shadowserver.org
- CVE-2015-20122no está en el catálogo de CISA
Yonyou · A6 OA
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION
Fuentes: cve.org
- CVE-2026-18143Crítica9.8no está en el catálogo de CISA
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the ra
Fuentes: patchstack.com
- CVE-2025-9090vista por sensoresno está en el catálogo de CISA
Tenda · ac20_firmware
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma
Fuentes: linkedin.com · api.vulncheck.com
- CVE-2024-5522vista por sensoresno está en el catálogo de CISA
bplugins · html5_video_player
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Fuentes: dashboard.shadowserver.org
- CVE-2026-33057vista por sensoresno está en el catálogo de CISA
mesop-dev · mesop
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings unconditionally without authentication measures, yielding standard Unres
Fuentes: api.vulncheck.com
- CVE-2026-93622no está en el catálogo de CISA
NicolasKulka · WPS Limit Login
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
Fuentes: patchstack.com
- CVE-2026-93399Crítica9.1no está en el catálogo de CISA
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly
Fuentes: patchstack.com
- CVE-2026-88996Media6.1no está en el catálogo de CISA
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input s
Fuentes: patchstack.com
- CVE-2026-62062Alta8.8no está en el catálogo de CISA
elementor · Website Builder
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.
Fuentes: patchstack.com
getgrav · grav
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories
Fuentes: bleepingcomputer.com
- CVE-2026-30633vista por sensoresno está en el catálogo de CISA
knowns-dev · knowns
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.
Fuentes: api.vulncheck.com · linkedin.com
- CVE-2026-18322Alta8.8no está en el catálogo de CISA
supsysticcom · Smart Popup by Supsystic
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrato
Fuentes: labs.itresit.es
- CVE-2022-28368no está en el catálogo de CISA
dompdf_project · dompdf
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
Fuentes: socradar.io
- CVE-2026-75949no está en el catálogo de CISA
cmsjunkie.com · J-BusinessDirectory extension for Joomla
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF t
Fuentes: previdian.com
- CVE-2026-66457Alta7.1no está en el catálogo de CISA
pixelite · events_manager
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.
Fuentes: cve.org
- CVE-2025-68472vista por sensoresno está en el catálogo de CISA
mindsdb · mindsdb
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. The PUT h
Fuentes: api.vulncheck.com
- CVE-2016-20080vista por sensoresno está en el catálogo de CISA
Brandfolder · Brandfolder
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_ab
Fuentes: dashboard.shadowserver.org
- CVE-2026-92229Crítica9.1no está en el catálogo de CISA
wpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form Builder
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before
Fuentes: patchstack.com
- CVE-2026-88062vista por sensoresno está en el catálogo de CISA
diegosouzapw · OmniRoute
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSyn
Fuentes: api.vulncheck.com · dashboard.shadowserver.org
iguazio · nuclio
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and common.Quote() for the
Fuentes: greynoise.io
FlowiseAI · Flowise
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/i
Fuentes: greynoise.io
senaite · senaite.core
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in sr
Fuentes: greynoise.io
Roundcube · Webmail
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
Fuentes: ess.coalitioninc.com · cyber.gc.ca
- CVE-2026-27960Crítica9.8vista por sensoresno está en el catálogo de CISA
citeum · opencti
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin a
Fuentes: dashboard.shadowserver.org · previdian.com
- CVE-2021-30134vista por sensoresno está en el catálogo de CISA
php_curl_class_project · php_curl_class
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
Fuentes: dashboard.shadowserver.org
- CVE-2018-13980vista por sensoresno está en el catálogo de CISA
zeta-producer · zeta_producer
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.
Fuentes: dashboard.shadowserver.org
- CVE-2026-86124Crítica9.8vista por sensoresno está en el catálogo de CISA
HKUDS · AutoAgent
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access t
Fuentes: api.vulncheck.com
- CVE-2026-84434Crítica9.8no está en el catálogo de CISA
Gravity Forms · Gravity Forms
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extensio
Fuentes: patchstack.com
- CVE-2026-42796vista por sensoresno está en el catálogo de CISA
workiva · arelle
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file throu
Fuentes: dashboard.shadowserver.org
- CVE-2023-46359vista por sensoresno está en el catálogo de CISA
hardy-barth · cph2_echarge_firmware
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
Fuentes: dashboard.shadowserver.org
- CVE-2023-29827vista por sensoresno está en el catálogo de CISA
ejs · ejs
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untr
Fuentes: dashboard.shadowserver.org
- CVE-2017-20284Alta7.5vista por sensoresno está en el catálogo de CISA
Caucho Technology, Inc. · Resin
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests
Fuentes: dashboard.shadowserver.org · previdian.com · cve.org
- CVE-2026-89013Alta7.5no está en el catálogo de CISA
dolibarr · dolibarr_erp\/crm
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation whil
Fuentes: previdian.com
- CVE-2026-86538Alta7.5no está en el catálogo de CISA
knowns-dev · knowns
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensit
Fuentes: previdian.com
- CVE-2026-40242vista por sensoresno está en el catálogo de CISA
getarcane · arcane
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. T
Fuentes: dashboard.shadowserver.org
- CVE-2026-32255vista por sensoresno está en el catálogo de CISA
kan · kan
Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the
Fuentes: dashboard.shadowserver.org
- CVE-2022-45362vista por sensoresno está en el catálogo de CISA
paytm · payment_gateway
Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.
Fuentes: dashboard.shadowserver.org
- CVE-2022-25497no está en el catálogo de CISA
cuppacms · cuppacms
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
Fuentes: previdian.com
- CVE-2026-66047Alta8.1no está en el catálogo de CISA
Proper Fraction · ProfilePress
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attac
Fuentes: patchstack.com
- CVE-2026-54196Media6.8no está en el catálogo de CISA
Crocoblock · jetformbuilder
Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.
Fuentes: patchstack.com
- CVE-2026-32996no está en el catálogo de CISA
Veeam · veeam_backup_\&_replication
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Fuentes: arcticwolf.com
- CVE-2022-0412vista por sensoresno está en el catálogo de CISA
templateinvaders · ti_woocommerce_wishlist
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL
Fuentes: dashboard.shadowserver.org
Issabel Foundation · Issabel Framework
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can
Fuentes: dashboard.shadowserver.org · cve.org
- CVE-2026-69255Alta8.8no está en el catálogo de CISA
FlowiseAI · Flowise
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base
Fuentes: previdian.com
- CVE-2025-9603vista por sensoresno está en el catálogo de CISA
Telesquare · tlr-2005ksh_firmware
A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to command injection. The attack may be performed from a remote location. The exploit
Fuentes: dashboard.shadowserver.org
- CVE-2024-58385Crítica9.8vista por sensoresno está en el catálogo de CISA
Yonyou · U8 CRM
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to exec
Fuentes: dashboard.shadowserver.org · cve.org
- CVE-2023-54398Crítica9.8no está en el catálogo de CISA
Yonyou · U8 Cloud
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction
Fuentes: cve.org
StellarWP · the_events_calendar
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() ob
Fuentes: patchstack.com
- CVE-2026-55786no está en el catálogo de CISA
FlytoHub · Flyto2 Core
## Unauthenticated Command Execution via HTTP MCP `execute_module` ### Summary The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-cont
Fuentes: previdian.com
- CVE-2026-23536no está en el catálogo de CISA
Red Hat · Red Hat OpenShift AI (RHOAI)
A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potential
Fuentes: previdian.com
- CVE-2026-18562Media6.1no está en el catálogo de CISA
pluginus · husky_-_products_filter_professional_for_woocommerce
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js()
Fuentes: patchstack.com
- CVE-2024-24112vista por sensoresno está en el catálogo de CISA
exrick · xmall
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
Fuentes: dashboard.shadowserver.org
- CVE-2022-32028vista por sensoresno está en el catálogo de CISA
car_rental_management_system_project · car_rental_management_system
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.
Fuentes: dashboard.shadowserver.org
- CVE-2022-32026vista por sensoresno está en el catálogo de CISA
car_rental_management_system_project · car_rental_management_system
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.
Fuentes: dashboard.shadowserver.org
- CVE-2022-32025vista por sensoresno está en el catálogo de CISA
car_rental_management_system_project · car_rental_management_system
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.
Fuentes: dashboard.shadowserver.org
- CVE-2022-32024vista por sensoresno está en el catálogo de CISA
car_rental_management_system_project · car_rental_management_system
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
Fuentes: dashboard.shadowserver.org
- CVE-2022-30047vista por sensoresno está en el catálogo de CISA
mingsoft · mcms
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
Fuentes: dashboard.shadowserver.org
- CVE-2022-27927vista por sensoresno está en el catálogo de CISA
microfinance_management_system_project · microfinance_management_system
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
Fuentes: dashboard.shadowserver.org
- CVE-2018-10736vista por sensoresno está en el catálogo de CISA
Nagios · Nagios XI
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Fuentes: dashboard.shadowserver.org
- CVE-2018-10735vista por sensoresno está en el catálogo de CISA
Nagios · Nagios XI
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Fuentes: dashboard.shadowserver.org
StellarWP · the_events_calendar
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during i
Fuentes: patchstack.com · wordfence.com
vitejs · vite
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are ap
Fuentes: previdian.com · f5.com
- CVE-2025-25252Media4.8no está en el catálogo de CISA
Fortinet · FortiOS
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possess
Fuentes: cydome.io
vitejs · vite
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it ex
Fuentes: f5.com
- CVE-2018-18084vista por sensoresno está en el catálogo de CISA
comsenz · duomicms
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
Fuentes: dashboard.shadowserver.org
- CVE-2017-8917vista por sensoresno está en el catálogo de CISA
Joomla! · Joomla!
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
Fuentes: dashboard.shadowserver.org
- CVE-2026-86206no está en el catálogo de CISA
N-able · N-central
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Fuentes: previdian.com
- CVE-2026-75981Alta7.2no está en el catálogo de CISA
cozmoslabs · TranslatePress – Translate Multilingual sites with AI Translation
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by transla
Fuentes: patchstack.com
Tencent · Sogou Input Method
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
Fuentes: gendigital.com
- CVE-2026-45695vista por sensoresno está en el catálogo de CISA
kopia · kopia
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and
Fuentes: dashboard.shadowserver.org
- CVE-2026-42031no está en el catálogo de CISA
okfn · ckan
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed
Fuentes: previdian.com
- CVE-2026-18884no está en el catálogo de CISA
wpgenie · WooCommerce Lottery
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m
Fuentes: patchstack.com
- CVE-2026-11613Crítica9.8no está en el catálogo de CISA
Divi Engine · Divi Ajax Filter
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the
Fuentes: patchstack.com
- CVE-2024-50340vista por sensoresno está en el catálogo de CISA
sensiolabs · symfony
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used
Fuentes: dashboard.shadowserver.org
- CVE-2024-36412vista por sensoresno está en el catálogo de CISA
salesagility · suitecrm
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
Fuentes: dashboard.shadowserver.org
- CVE-2022-1057vista por sensoresno está en el catálogo de CISA
varktech · pricing_deals_for_woocommerce
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
Fuentes: dashboard.shadowserver.org
Por qué una página aparte
Datos del catálogo Known Exploited Vulnerabilities de CISA, obra del Gobierno de EE. UU. en dominio público. Los plazos indicados obligan a las agencias federales estadounidenses (BOD 22-01); para el resto son una buena referencia de prioridad.
Datos de explotación: VulnCheck KEV. El catálogo de vulnerabilidades explotadas activamente es de CISA.