Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.20%—Arraytics TimeticsAI5/10/20266/10/2026
Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63.
AplazadaMedia (6.9)0.32%—Crossplane RuntimeAI4/10/20266/10/2026
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and…
AplazadaAlta (7.2)0.27%—Wp-buy Visitor Traffic Real Time StatisticsAI3/10/20266/10/2026
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaBaja (2)0.28%—Bytecodealliance WasmtimeAI2/10/20266/10/2026
Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after…
AplazadaAlta (7.2)0.19%—Visitors Traffic Real Time Statistics PROAI2/10/20262/10/2026
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers…
Pendiente de análisisCrítica (9.8)0.44%—Wikimedia EasytimelineAI29/9/20261/10/2026
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
AplazadaCrítica (9.8)0.75%—Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI29/9/202629/9/2026
An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
Pendiente de análisisMedia (4.3)0.21%—HCL SametimeAI24/9/202624/9/2026
HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability.
AplazadaAlta (7.6)0.29%—UltimeterAI23/9/202623/9/2026
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
AplazadaMedia (5.3)0.21%—Product Badge Label Countdown Timer FOR WoocommerceAI23/9/202623/9/2026
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
AplazadaMedia (6.5)0.45%—Supabase RealtimeAI21/9/202624/9/2026
Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that…
AplazadaBaja (1.9)0.35%—LeantimeAI21/9/202621/9/2026
A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has…
AplazadaBaja (2)0.36%—LeantimeAI21/9/202621/9/2026
A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been…
AplazadaCrítica (9.4)0.67%—Openpanel Js-runtimeAI19/9/20262/10/2026
OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and…
AplazadaAlta (7.1)0.25%—Visitor Traffic Real Time Statistics PROAI17/9/202617/9/2026
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
AplazadaAlta (7.1)0.53%—LeantimeAI16/9/202617/9/2026
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
Pendiente de análisisCrítica (9.5)0.69%—Arista EOSAIP4runtimeAI16/9/202617/9/2026
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the…
AplazadaAlta (8.5)3.4%💥 PoCIptime C200eAI15/9/202615/9/2026
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.47%—Sourcecodester Class AND Exam Timetabling SystemAI14/9/202615/9/2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be…
AplazadaAlta (7.5)0.60%—Xiongmai Xm530AIXiongmai Sofia IPCAIXiongmai Happytime Rtsp ServerAI11/9/202622/9/2026
An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over…
AplazadaMedia (6.4)0.36%—Bold-themes Bold Timeline LiteAI11/9/202611/9/2026
The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaAlta (8.1)0.50%—Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 20268/9/202629/9/2026
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI7/9/20268/9/2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI6/9/20268/9/2026
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is…
AplazadaMedia (5.5)0.43%—Sourcecodester Class AND Exam Timetabling SystemAI6/9/202611/9/2026
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed…
Orbitaley — Vulnerabilidades