Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-70458 2026-08-13 HIGH 8.2 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while…
CVE-2026-70454 2026-08-13 HIGH 8.0 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting…
CVE-2026-6471 2026-08-13 HIGH 7.2 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…
CVE-2026-6821 2026-08-12 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have…
CVE-2026-6387 2026-08-13 HIGH 7.0 A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
CVE-2026-6469 2026-08-13 LOW 3.8 Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run…
CVE-2026-6464 2026-08-13 HIGH 8.1 Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM…
CVE-2026-67991 2026-08-13 HIGH 7.5 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive…
CVE-2026-67990 2026-08-13 MEDIUM 5.4 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that…
CVE-2026-67986 2026-08-13 HIGH 8.4 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval…
CVE-2026-66704 2026-08-13 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion
CVE-2026-66700 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover
CVE-2026-66698 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SureDash
CVE-2026-66697 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
CVE-2026-66693 2026-08-13 MEDIUM 6.5 Subscriber Broken Access Control in Motors
CVE-2026-66691 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Access Control in Nokri
CVE-2026-66689 2026-08-13 MEDIUM 6.3 Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker
CVE-2026-66687 2026-08-13 MEDIUM 6.5 Customer Cross Site Scripting (XSS) in WpBookingly
CVE-2026-66661 2026-08-13 HIGH 7.7 Subscriber Privilege Escalation in Directories Pro
CVE-2026-66660 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-66658 2026-08-13 HIGH 8.5 Subscriber SQL Injection in Reviewer
CVE-2026-66657 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Biagiotti Core
CVE-2026-66656 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Foton Core
CVE-2026-66655 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce
CVE-2026-66654 2026-08-13 MEDIUM 6.0 Subscriber Server Side Request Forgery (SSRF) in Vehica Core
CVE-2026-66653 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Barista
CVE-2026-66478 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Church Admin
CVE-2026-66472 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Everest Backup
CVE-2026-66471 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Accordion
CVE-2026-66469 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Arvow AI SEO Writer
CVE-2026-66468 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce
CVE-2026-66467 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in FluentCommunity
CVE-2026-66466 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
CVE-2026-66465 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Cartify
CVE-2026-66464 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Internal Link Optimiser
CVE-2026-66463 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in iCARRY
CVE-2026-66462 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in WooCommerce Appointments
CVE-2026-66461 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce
CVE-2026-66460 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in AfterShip Tracking
CVE-2026-66459 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in AI for SEO
CVE-2026-66458 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in RealPress
CVE-2026-66456 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft
CVE-2026-66455 2026-08-13 MEDIUM 6.0 Subscriber Broken Access Control in ReactPress
CVE-2026-66454 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in WP Social Avatar
CVE-2026-66453 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Salon booking system
CVE-2026-66450 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Geo Mashup
CVE-2026-66449 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Geo Mashup
CVE-2026-66446 2026-08-13 CRITICAL 9.3 Subscriber SQL Injection in If-So Dynamic Content Personalization
CVE-2026-66444 2026-08-13 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Payment Forms for Paystack
CVE-2026-66443 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in REST API Log