Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.48% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.8) | 0.45% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Media (6.5) | 0.35% | 💥 PoC | Adamhathcock Sharpcompress | 26/5/2026 | 24/7/2026 | SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary… | |
| Aplazada | Alta (7.1) | 0.30% | — | Adamlabs Wordpress Photo GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Padam Shankhadev Nepali-post-dateAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Nepali Post Date nepali-post-date allows Stored XSS.This issue affects Nepali Post Date: from n/a through <= 5.1.1. | |
| Aplazada | Crítica (9.8) | 0.39% | 💥 PoC | Adam Nowak Buddypress HumanityAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.9) | 0.77% | — | Adamskaat Countdown & ClockAI | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a through <= 2.8.8. | |
| Aplazada | Alta (7.1) | 0.39% | — | Padam Shankhadev Ps-ads-proAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Ps Ads Pro ps-ads-pro allows Reflected XSS.This issue affects Ps Ads Pro: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.9) | 0.39% | — | Adamskaat Countdown AND ClockAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamskaat Countdown & Clock countdown-builder allows Stored XSS.This issue affects Countdown & Clock: from n/a through <= 3.0.8. | |
| Aplazada | Media (4.3) | 0.26% | — | Read More BY AdamAI | 12/10/2024 | 17/6/2026 | The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete read more buttons. | |
| Aplazada | Alta (7) | 0.22% | — | Advantech Adam-5630AI | 27/9/2024 | 17/6/2026 | Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP request and are executed by the device automatically, without… | |
| Analizada | Alta (8.5) | 0.41% | — | Advantech Adam-5630 Firmware | 27/9/2024 | 17/6/2026 | Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user. | |
| Analizada | Alta (8.7) | 0.31% | — | Advantech Adam 5550-firmware | 27/9/2024 | 17/6/2026 | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output. | |
| Analizada | Media (6.8) | 0.37% | — | Advantech Adam-5550 Firmware | 27/9/2024 | 17/6/2026 | Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. | |
| Analizada | Media (6.9) | 0.22% | — | Advantech Adam-5630 Firmware | 27/9/2024 | 17/6/2026 | Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process. | |
| Analizada | Alta (8.5) | 0.22% | — | Advantech Adam-5630 Firmware | 27/9/2024 | 17/6/2026 | Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other. | |
| Analizada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack | |
| Modificada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (6.5) | 0.41% | — | Adam Dehaven Perfect PullquotesAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5. | |
| Aplazada | Alta (7.1) | 0.35% | — | Adam Bowen TAX Rate UploadAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5. | |
| Aplazada | Alta (7.1) | 0.18% | — | Adam Bowen TAX Rate UploadAI | 2/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5. | |
| Modificada | Crítica (9.8) | 0.62% | — | Adampos Mobilmen EL Terminali Yazilimi | 23/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | |
| Modificada | Alta (8.8) | 0.36% | — | Read More BY Adam Project Read More BY Adam | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Read more By Adam plugin <= 1.1.8 at WordPress. | |
| Modificada | Crítica (9.8) | 1.2% | — | Advantech Adam-3600 Firmware | 4/2/2022 | 17/6/2026 | The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions. |