Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.48% | — | Wowoptin Next-gen Popup MakerAI | 21/3/2026 | 17/6/2026 | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that passes… | |
| Analizada | Alta (7.5) | 0.41% | — | Frappe Erpnext | 20/3/2026 | 17/6/2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has been fixed in… | |
| Aplazada | Alta (8.8) | 0.45% | — | Nextgen GalleryAI | 18/3/2026 | 17/6/2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include… | |
| Analizada | Media (6.3) | 0.53% | 💥 PoC | Vercel Next.js | 18/3/2026 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement… | |
| Analizada | Media (6.9) | 0.84% | — | Vercel Next.js | 18/3/2026 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique… | |
| Analizada | Media (6.9) | 0.84% | — | Vercel Next.js | 18/3/2026 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups.… | |
| Analizada | Media (5.3) | 0.23% | 💥 PoC | Vercel Next.js | 18/3/2026 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification… | |
| Analizada | Baja (2.3) | 0.21% | — | Vercel Next.js | 18/3/2026 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque… | |
| Analizada | Alta (8.8) | 0.42% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based… | |
| Analizada | Alta (8.8) | 0.42% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by… | |
| Analizada | Media (5.1) | 0.21% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe… | |
| Analizada | Media (5.1) | 0.32% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations interface. Attackers can submit POST requests to the locations.php endpoint with JavaScript payloads in the location_name field to execute arbitrary code in administrator… | |
| Analizada | Media (6.9) | 0.19% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to… | |
| Analizada | Media (5.1) | 0.24% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is… | |
| Analizada | Media (5.1) | 0.27% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users. | |
| Analizada | Media (5.1) | 0.27% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple parameters that are not properly sanitized. Attackers can craft requests with injected script payloads in vulnerable… | |
| Analizada | Media (6.9) | 0.18% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized actions when logged-in users visit them,… | |
| Analizada | Alta (7.3) | 0.12% | — | Forcepoint Next Generation Firewall | 11/3/2026 | 17/6/2026 | Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10. | |
| Aplazada | Media (6.4) | 0.34% | 💥 PoC | Nextscripts Social Networks Auto PosterAI | 10/3/2026 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.58% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Analizada | Alta (7.7) | 0.44% | — | Opennextjs Opennext FOR Cloudflare | 4/3/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/cloudflare worker template includes a /cdn-cgi/image/ handler intended for development use only. In production, Cloudflare's… | |
| Analizada | Media (5.4) | 0.15% | — | IBM Engineering Requirements Management Doors Next | 3/3/2026 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions. | |
| Modificada | Crítica (9.8) | 2.4% | 💥 Exploit | Epati Antikor Next Generation Firewall | 25/2/2026 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301. | |
| Analizada | Crítica (9.3) | 0.44% | — | Frappe Erpnext | 21/2/2026 | 17/6/2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1. | |
| Aplazada | Alta (7.5) | 0.30% | — | Xlplugins Nextmove LiteAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0. |