Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

51 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (8.8)0.45%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AnalizadaMedia (6.5)0.35%💥 PoCAdamhathcock Sharpcompress26/5/202624/7/2026
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary…
AplazadaAlta (7.1)0.30%—Adamlabs Wordpress Photo GalleryAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0.
AplazadaMedia (6.5)0.27%—Padam Shankhadev Nepali-post-dateAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Nepali Post Date nepali-post-date allows Stored XSS.This issue affects Nepali Post Date: from n/a through <= 5.1.1.
AplazadaCrítica (9.8)0.39%💥 PoCAdam Nowak Buddypress HumanityAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.
AplazadaCrítica (9.9)0.77%—Adamskaat Countdown & ClockAI1/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a through <= 2.8.8.
AplazadaAlta (7.1)0.39%—Padam Shankhadev Ps-ads-proAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Ps Ads Pro ps-ads-pro allows Reflected XSS.This issue affects Ps Ads Pro: from n/a through <= 1.0.0.
AplazadaMedia (5.9)0.39%—Adamskaat Countdown AND ClockAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamskaat Countdown & Clock countdown-builder allows Stored XSS.This issue affects Countdown & Clock: from n/a through <= 3.0.8.
AplazadaMedia (4.3)0.26%—Read More BY AdamAI12/10/202417/6/2026
The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete read more buttons.
AplazadaAlta (7)0.22%—Advantech Adam-5630AI27/9/202417/6/2026
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without…
AnalizadaAlta (8.5)0.41%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.
AnalizadaAlta (8.7)0.31%—Advantech Adam 5550-firmware27/9/202417/6/2026
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
AnalizadaMedia (6.8)0.37%—Advantech Adam-5550 Firmware27/9/202417/6/2026
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
AnalizadaMedia (6.9)0.22%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
AnalizadaAlta (8.5)0.22%—Advantech Adam-5630 Firmware27/9/202417/6/2026
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.
AnalizadaAlta (8.8)0.31%—Adamsolymosi Contentlock12/7/202417/6/2026
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack
ModificadaAlta (8.8)0.31%—Adamsolymosi Contentlock12/7/202417/6/2026
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
ModificadaAlta (8.8)0.31%—Adamsolymosi Contentlock12/7/202417/6/2026
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AplazadaMedia (6.5)0.41%—Adam Dehaven Perfect PullquotesAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5.
AplazadaAlta (7.1)0.35%—Adam Bowen TAX Rate UploadAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.
AplazadaAlta (7.1)0.18%—Adam Bowen TAX Rate UploadAI2/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.
ModificadaCrítica (9.8)0.62%—Adampos Mobilmen EL Terminali Yazilimi23/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.
ModificadaAlta (8.8)0.36%—Read More BY Adam Project Read More BY Adam23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Read more By Adam plugin <= 1.1.8 at WordPress.
ModificadaCrítica (9.8)1.2%—Advantech Adam-3600 Firmware4/2/202217/6/2026
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.