832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-30048
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when the chat history is reloaded. The issue is reproducible across multiple independent implementations of the widget, indicating that the vulnerability resides in the product itself rather than in a specific website configuration.

CVE-2026-24069
SAST Cloud
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 2 PoCs

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

CVE-2026-4274
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team membership assignment. Mattermost Advisory ID: MMSA-2026-00574

CVE-2026-40212
Skyline Web
5.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

CVE-2026-5306
Check & Log Email Web Windows
5.4
MEDIUM
EPSS
0.1%
2026 1 PoC

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

CVE-2026-31153
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2026-0901
Chrome General
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2026-0972
GoAnywhere MFT General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-74 1 PoC

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

CVE-2026-36341
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

CVE-2026-0999
Mattermost General
5.4
MEDIUM
EPSS
0.1%
2026 CWE-303 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548

CVE-2026-26269
vim General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-121 1 PoC

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.

CVE-2026-20122
🔥 KEV Cisco Catalyst SD-WAN Manager Web Networking
5.4
MEDIUM
EPSS
1.1%
2026 CWE-648 1 PoC

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system&nbsp;and gain vmana

CVE-2026-2712
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance Web Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke ad

CVE-2026-2322
Chrome General
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-4430
LibreOffice General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-787 1 PoC

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

CVE-2026-4829
Server General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-287 1 PoC

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

CVE-2026-38948
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

CVE-2026-0903
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)

CVE-2026-4847
muucmf General
5.3
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-5178
A3300R General
5.3
MEDIUM
EPSS
0.7%
2026 CWE-77 1 PoC

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.