Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.49% | — | Minio Java SDKAI | 30/9/2025 | 17/6/2026 | MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their… | |
| Aplazada | Media (6.5) | 0.21% | 💥 PoC | Eachitaly Wireless Mini RouterAI | 29/9/2025 | 17/6/2026 | Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands. | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.20% | — | Agency Dominion INC Fusion Page Builder Extension GalleryAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery fusion-extension-gallery allows Stored XSS.This issue affects Fusion Page Builder : Extension – Gallery: from n/a through <= 1.7.6. | |
| Analizada | Crítica (9.8) | 0.55% | — | Blackmagicdesign Atem Mini PRO Firmware | 22/9/2025 | 17/6/2026 | The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and even internal… | |
| Aplazada | Alta (7.5) | 0.28% | — | Blackmagic Atem Mini PROAI | 22/9/2025 | 17/6/2026 | The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for controlling streaming, recording, formatting storage devices, and system reboot. This interface, referred to as the "ATEM Ethernet Protocol 1.0", provides complete device… | |
| Aplazada | Alta (8.1) | 0.37% | — | Miniorange OTP Verification With FirebaseAI | 19/9/2025 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator.… | |
| Aplazada | Baja (1.3) | 0.25% | — | DJI Mavic SparkAIDJI Mavic AIRAIDJI Mavic MiniAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attacker needs to be present on the local network. A high complexity level is… | |
| Aplazada | Alta (7.5) | 0.43% | — | ALL IN ONE MinifierAI | 11/9/2025 | 17/6/2026 | The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Miniorange Malware ScannerAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through <= 16.8. | |
| Aplazada | Media (5.5) | 0.26% | — | Amministrazione TrasparenteAI | 31/8/2025 | 17/6/2026 | The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Alta (8.4) | 0.33% | 💥 Exploit | Mini-stream WM DownloaderAI | 30/8/2025 | 16/6/2026 | WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application fails to properly validate input length, allowing an attacker to overwrite structured exception handler (SEH) records and execute arbitrary code. Exploitation occurs locally when a… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Miniorange Custom API FOR WPAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2. | |
| Aplazada | Crítica (9.3) | 0.42% | — | Miniorange Custom API FOR WPAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2. | |
| Aplazada | Media (6.5) | 0.43% | — | Miniorange Prevent Files Folders AccessAI | 20/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0. | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Miniweb Http ServerAI | 1/8/2025 | 16/6/2026 | An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, followed by a .mof… | |
| Aplazada | Alta (7.5) | 0.34% | — | Thememove MinimogwpAI | 26/7/2025 | 17/6/2026 | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add… | |
| Analizada | Media (4.8) | 0.29% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. | |
| Analizada | Alta (7.5) | 0.66% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | |
| Analizada | Media (4.9) | 0.58% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | |
| Analizada | Media (4.9) | 0.55% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. |