Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.18%—Contact Form 7AISalesforceAICrmperks Integration FOR Contact Form 7 AND SalesforceAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.
AplazadaMedia (4.3)0.25%—Crmperks Integration FOR Pipedrive AND Contact Form 7 Wpforms Elementor Ninja FormsAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.
AplazadaMedia (5.3)0.58%—Alexacrm Dynamics 365 IntegrationAI14/5/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.
AnalizadaMedia (6.5)1.2%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaMedia (6.5)1.2%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (8.8)1.3%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (7.5)0.81%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AnalizadaCrítica (9.6)1.4%—Softing EdgeaggregatorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaAlta (7.5)1.4%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AplazadaMedia (5.3)0.55%—Streamweasels Twitch IntegrationAI24/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StreamWeasels StreamWeasels Twitch Integration.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.8.
ModificadaAlta (8.8)0.51%—Themekraft Buddypress Woocommerce MY Account Integration18/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20.
ModificadaCrítica (9.8)1.3%—Videowhisper Live Streaming Integration3/4/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.
AplazadaMedia (6.5)0.35%—Streamweasels Twitch IntegrationAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StreamWeasels StreamWeasels Twitch Integration allows Stored XSS.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.5.
AnalizadaMedia (4.9)0.54%—IBM Integration BUSIBM APP Connect Enterprise26/3/202417/6/2026
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. IBM X-Force ID: 280893.
AplazadaAlta (8.8)0.81%—Themekraft Buddypress Woocommerce MY Account IntegrationAI23/3/202417/6/2026
The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it possible for authenticated attackers,…
AplazadaMedia (6.1)1.6%💥 PoCAdvancedformintegration Advanced Form IntegrationAI20/3/202417/6/2026
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of…
ModificadaMedia (6.5)0.24%—IBM Integration BUS14/3/202417/6/2026
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.
AnalizadaMedia (5.3)0.45%—SAP Netweaver Process Integration12/3/202417/6/2026
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
AnalizadaMedia (5.3)0.38%—Hitachi Vantara Pentaho Data Integration AND Analytics28/2/202417/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
ModificadaAlta (7.5)4.6%—Netapp Active IQ Unified ManagerNetapp Oncommand Workflow AutomationRedhat FuseRedhat Integration Camel FOR Spring Boot+519/2/20242/10/2026
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits…
ModificadaMedia (6.5)0.61%—IBM Integration BUS9/2/202417/6/2026
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972.
ModificadaMedia (6.5)0.38%—Magicsoftware Magic XPI Integration Platform6/2/202417/6/2026
The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.