Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Wow-company WP CoderAI | 7/10/2026 | 7/10/2026 | The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site. | |
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Aplazada | Alta (8.7) | 0.32% | — | Brainzcompany Zenius EMSAI | 11/9/2026 | 18/9/2026 | Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109). | |
| Aplazada | Media (6.5) | 0.17% | — | WOO Transport CompanyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | |
| Aplazada | Media (6.6) | 0.52% | — | Wow-company Counter BOXAI | 17/6/2026 | 17/6/2026 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Seafood CompanyAI | 17/6/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. | |
| Aplazada | Alta (8.8) | 0.27% | — | Wow-company WOW FormsAI | 9/6/2026 | 21/7/2026 | Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Alta (7.2) | 1.7% | — | Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI | 4/5/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thamerex Work AND Travel CompanyAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.24% | — | Company Posts FOR LinkedinAI | 21/3/2026 | 17/6/2026 | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.0. This is due to a missing capability check on the `linkedin_company_post_reset_handler()` function hooked to `admin_post_reset_linkedin_company_post`. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.20% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 27/1/2026 | 17/6/2026 | SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted. | |
| Aplazada | Media (6.5) | 0.19% | — | Micro.company Form TO ChatAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.company Form to Chat App form-to-chat allows Stored XSS.This issue affects Form to Chat App: from n/a through <= 1.2.5. | |
| Aplazada | Alta (8.1) | 0.30% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 13/1/2026 | 17/6/2026 | SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted. | |
| Aplazada | Media (6.6) | 0.22% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 13/1/2026 | 17/6/2026 | SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application. | |
| Aplazada | Media (5.1) | 0.18% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 13/1/2026 | 17/6/2026 | SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application. | |
| Aplazada | Media (4.3) | 0.21% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 13/1/2026 | 17/6/2026 | Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted. | |
| Aplazada | Media (4.3) | 0.13% | — | SAP Fiori APP Intercompany Balance ReconciliationAI | 13/1/2026 | 17/6/2026 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an… | |
| Aplazada | Alta (8.7) | 0.32% | — | THE QT Company QTAI | 3/12/2025 | 29/7/2026 | Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the… | |
| Analizada | Media (5.5) | 0.39% | — | Torrahclef Company Website CMS | 23/11/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.39% | — | Torrahclef Company Website CMS | 23/11/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (6.4) | 0.18% | — | WP Company InfoAI | 21/11/2025 | 17/6/2026 | The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'social-networks' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Esbi Information AND Telecommunication Industry AND Trade Limited Company Auto Service SoftwareAI | 18/9/2025 | 17/6/2026 | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection. This issue affects Auto Service Software: before v.2025.10.01. | |
| Aplazada | Media (6.9) | 0.22% | — | Perl PreparecompanyprofileexportjsonAI | 27/8/2025 | 17/6/2026 | In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Torod Company FOR Information Technology TorodAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod torod allows SQL Injection.This issue affects Torod: from n/a through <= 2.1. | |
| Analizada | Baja (2) | 0.54% | — | Oretnom23 Simple Company Website | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… |