Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.20% | — | Arraytics TimeticsAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63. | |
| Aplazada | Media (6.9) | 0.32% | — | Crossplane RuntimeAI | 4/10/2026 | 6/10/2026 | A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and… | |
| Aplazada | Alta (7.2) | 0.27% | — | Wp-buy Visitor Traffic Real Time StatisticsAI | 3/10/2026 | 6/10/2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Baja (2) | 0.28% | — | Bytecodealliance WasmtimeAI | 2/10/2026 | 6/10/2026 | Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after… | |
| Aplazada | Alta (7.2) | 0.19% | — | Visitors Traffic Real Time Statistics PROAI | 2/10/2026 | 2/10/2026 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Wikimedia EasytimelineAI | 29/9/2026 | 1/10/2026 | XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI | 29/9/2026 | 29/9/2026 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | HCL SametimeAI | 24/9/2026 | 24/9/2026 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability. | |
| Aplazada | Alta (7.6) | 0.29% | — | UltimeterAI | 23/9/2026 | 23/9/2026 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Product Badge Label Countdown Timer FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products. | |
| Aplazada | Media (6.5) | 0.45% | — | Supabase RealtimeAI | 21/9/2026 | 24/9/2026 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that… | |
| Aplazada | Baja (1.9) | 0.35% | — | LeantimeAI | 21/9/2026 | 21/9/2026 | A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2) | 0.36% | — | LeantimeAI | 21/9/2026 | 21/9/2026 | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Openpanel Js-runtimeAI | 19/9/2026 | 2/10/2026 | OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | |
| Aplazada | Alta (7.1) | 0.53% | — | LeantimeAI | 16/9/2026 | 17/9/2026 | Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins. | |
| Pendiente de análisis | Crítica (9.5) | 0.69% | — | Arista EOSAIP4runtimeAI | 16/9/2026 | 17/9/2026 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the… | |
| Aplazada | Alta (8.5) | 3.4% | 💥 PoC | Iptime C200eAI | 15/9/2026 | 15/9/2026 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Alta (7.5) | 0.60% | — | Xiongmai Xm530AIXiongmai Sofia IPCAIXiongmai Happytime Rtsp ServerAI | 11/9/2026 | 22/9/2026 | An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over… | |
| Aplazada | Media (6.4) | 0.36% | — | Bold-themes Bold Timeline LiteAI | 11/9/2026 | 11/9/2026 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (8.1) | 0.50% | — | Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 7/9/2026 | 8/9/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 11/9/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… |