Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 1.7% | ⚠ Explotación activa💥 PoC | Aquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+1 | 23/3/2026 | 17/6/2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This… | |
| Aplazada | Media (6.4) | 0.24% | — | Tour Activity Operator Plugin FOR TourcmsAI | 21/3/2026 | 17/6/2026 | The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link shortcode in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.1) | 0.21% | — | IBM Cics Transaction Gateway | 16/3/2026 | 17/6/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls. | |
| Aplazada | Media (6.5) | 0.22% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.7. | |
| Aplazada | Baja (2.1) | 0.41% | — | Alfresco ActivitiAI | 12/3/2026 | 17/6/2026 | A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This… | |
| Analizada | Crítica (9.3) | 0.83% | — | Xygeni-action | 11/3/2026 | 17/6/2026 | xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However,… | |
| Aplazada | Alta (7.7) | 0.44% | — | Activitypub FederationAIPict-rsAIJoin-lemmy LemmyAI | 6/3/2026 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Loopus WP Attractive Donations SystemAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from… | |
| Aplazada | Alta (7.1) | 0.26% | — | Lambertgroup Uberslider MouseinteractionAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider MouseInteraction uberSlider_mouseinteraction allows Reflected XSS.This issue affects UberSlider MouseInteraction: from n/a through <= 2.3. | |
| Aplazada | Alta (8.1) | 0.54% | — | Qodeinteractive WanderlandAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.5. | |
| Modificada | Alta (8.8) | 0.79% | — | Apache Activemq | 4/3/2026 | 17/6/2026 | Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly… | |
| Analizada | Alta (8.3) | 0.40% | — | Broadcom Brocade Active Support Connectivity Gateway | 3/3/2026 | 17/6/2026 | Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric. | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI | 2/3/2026 | 17/6/2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | |
| Aplazada | Alta (8.1) | 0.53% | — | Qodeinteractive FivestarAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes FiveStar fivestar allows PHP Local File Inclusion.This issue affects FiveStar: from n/a through <= 1.7. | |
| Analizada | Baja (2.3) | 0.19% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the… | |
| Analizada | Media (6.5) | 0.38% | — | Refraction-networking Utls | 20/2/2026 | 17/6/2026 | uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec. This allowed an… | |
| Analizada | Alta (8.1) | 2.1% | — | Aquasec Trivy Action | 19/2/2026 | 17/6/2026 | Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables. The action writes `export VAR=<input>`… | |
| Aplazada | Baja (3.8) | 0.24% | — | Creativeinteractivemedia Real 3D FlipbookAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Melapress WP Activity LOGAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 5.5.4. | |
| Aplazada | Media (6.4) | 0.25% | — | InteractivecalculatorAI | 18/2/2026 | 17/6/2026 | The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interactivecalculator' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.18% | — | IBM Financial Transaction Manager FOR ACH ServicesAIIBM Financial Transaction Manager FOR Check ServicesAI | 17/2/2026 | 17/6/2026 | IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim Fix 027 IBM Financial Transaction Manager for Check Services v3 (Multiplatforms) is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary… | |
| Aplazada | Media (6.5) | 0.30% | — | Winter Activity LOGAI | 12/2/2026 | 17/6/2026 | The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (8.5) | 0.13% | — | Activefax ServerAI | 11/2/2026 | 17/6/2026 | ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative… | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… |