832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-40212
Skyline Web
5.4
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

CVE-2026-20122
🔥 KEV Cisco Catalyst SD-WAN Manager Web Networking
5.4
MEDIUM
EPSS
1.1%
2026 CWE-648 1 PoC

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmana

CVE-2026-2322
Chrome General
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-24069
SAST Cloud
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 2 PoCs

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

CVE-2026-31153
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2026-0901
Chrome General
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

CVE-2026-0999
Mattermost General
5.4
MEDIUM
EPSS
0.1%
2026 CWE-303 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548

CVE-2026-26269
vim General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-121 1 PoC

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.

CVE-2026-2712
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance Web Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking `Updraft_Smush_Manager_Commands` methods without verifying user capabilities, nonce tokens, or the allowed commands whitelist that the normal AJAX handler (`updraft_smush_ajax`) enforces. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke ad

CVE-2026-4829
Server General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-287 1 PoC

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

CVE-2026-0903
Chrome Windows
5.4
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)

CVE-2026-4274
Mattermost General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team membership assignment. Mattermost Advisory ID: MMSA-2026-00574

CVE-2026-30048
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when the chat history is reloaded. The issue is reproducible across multiple independent implementations of the widget, indicating that the vulnerability resides in the product itself rather than in a specific website configuration.

CVE-2026-5306
Check & Log Email Web Windows
5.4
MEDIUM
EPSS
0.1%
2026 1 PoC

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

CVE-2026-38948
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

CVE-2026-4430
LibreOffice General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-787 1 PoC

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

CVE-2026-36341
Software Genérico Web
5.4
MEDIUM
EPSS
0.0%
2026 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

CVE-2026-0972
GoAnywhere MFT General
5.4
MEDIUM
EPSS
0.0%
2026 CWE-74 1 PoC

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

CVE-2026-3163
Website Link Extractor General
5.3
MEDIUM
EPSS
0.1%
2026 CWE-918 1 PoC

A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-2693
CyreneAdmin Web
5.3
MEDIUM
EPSS
0.0%
2026 CWE-285 1 PoC

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper authorization. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.