Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 2.2% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 10/12/2025 | 25/9/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Analizada | Media (5.4) | 0.17% | — | IBM Websphere Application Server | 8/12/2025 | 7/10/2026 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious… | |
| Modificada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Mstoreapp Mobile APPAIMstoreapp Mobile MultivendorAI | 21/11/2025 | 17/6/2026 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address. | |
| Aplazada | Alta (8.8) | 4.2% | 💥 PoC | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature. | |
| Aplazada | Alta (7.1) | 0.18% | — | Amauri Wpmobile.appAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71. | |
| Analizada | Baja (2.7) | 0.29% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of… | |
| Analizada | Media (4.9) | 0.33% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of… | |
| Analizada | Media (4.9) | 0.33% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful… | |
| Analizada | Media (4.9) | 0.33% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this… | |
| Analizada | Media (4.9) | 0.31% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of… | |
| Analizada | Media (4.9) | 0.41% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this… | |
| Analizada | Baja (2.7) | 0.29% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks… | |
| Analizada | Media (4.9) | 0.33% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful… | |
| Analizada | Alta (7.2) | 0.35% | — | Oracle ZFS Storage Appliance KIT | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of… | |
| Analizada | Media (6.5) | 0.96% | — | Zohocorp Manageengine Applications Manager | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | |
| Aplazada | Baja (0.9) | 0.20% | — | Tomofun Furbo Mobile APPAI | 12/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has… | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Analizada | Crítica (9.4) | 0.16% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 2/10/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read… | |
| Analizada | Alta (8.2) | 0.44% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 2/10/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The hashing is performed via PHP's `hash()` function in multiple files (server_write_requests_users.php, update_database.php,… | |
| Analizada | Crítica (10) | 0.75% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 30/9/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh group 'NOPASSWD: ALL'. Possession of the matching private key gives… | |
| Analizada | Crítica (9.5) | 0.47% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 29/9/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS certificate validation. An attacker who can intercept HTTPS… | |
| Analizada | Crítica (9.2) | 0.41% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 29/9/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (printerlogic/pi, printerlogic/printer-admin-api, and printercloud/pi). The keys are… | |
| Analizada | Alta (8.5) | 0.59% | — | Vasion Virtual Appliance ApplicationVasion Virtual Appliance Host | 29/9/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a protection mechanism failure vulnerability within the file_get_contents() function. When an administrator configures a printer’s hostname (or similar callback… |