Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.80%—Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO13/1/202617/6/2026
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
AnalizadaCrítica (9.1)1.6%—Zohocorp Manageengine Adselfservice Plus13/1/202617/6/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
AplazadaAlta (8.7)0.44%—Siemens Simatic ET 200al IM 157-1 PNAISiemens Simatic ET 200mp IM 155-5 PN HFAISiemens Simatic ET 200sp IM 155-6 MF HFAISiemens Simatic ET 200sp IM 155-6 PN HAAI+813/1/202617/6/2026
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All…
AplazadaMedia (6.9)0.30%—A-plus Video Technologies NVRAI12/1/202617/6/2026
Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access the debug page and obtain device status information.
AnalizadaCrítica (9.4)0.73%—Dromara Ruoyi-vue-plus8/1/202617/6/2026
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
AplazadaAlta (7.1)0.18%—Gopiplus Scroll RSS ExcerptAI8/1/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Scroll rss excerpt scroll-rss-excerpt allows Reflected XSS.This issue affects Scroll rss excerpt: from n/a through <= 5.0.
AplazadaMedia (6.5)0.21%—Theplus Innovation THE Plus Addons FOR Elementor PROAI7/1/20267/10/2026
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7.
AplazadaAlta (7.1)0.28%—Wppa WP Photo Album PlusAI7/1/20267/10/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (6.5)0.15%—Posimyth THE Plus Addons FOR Elementor Page Builder LiteAI5/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.3.3.
AnalizadaBaja (2)0.41%—Newbee-ltd Newbee-mall-plus30/12/202517/6/2026
A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/common/UploadController.java of the component Product Information Edit Page. This manipulation of the argument File causes unrestricted upload. The attack may be initiated…
AplazadaMedia (4.3)0.18%—Kraftplugins Demo Importer PlusAI30/12/20257/10/2026
Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8.
AplazadaMedia (5.1)0.16%—Devolo Dlan 500 AV Wireless PlusAI24/12/202517/6/2026
Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a…
AplazadaMedia (5.1)0.21%—AVE DominaplusAI24/12/202517/6/2026
AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.
ModificadaMedia (5.1)0.22%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a…
AnalizadaAlta (8.7)0.78%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting…
AnalizadaCrítica (9.3)0.39%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.
ModificadaAlta (7.1)0.49%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring…
AnalizadaAlta (7.1)0.47%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and…
ModificadaAlta (8.7)0.48%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system…
AnalizadaAlta (8.7)0.60%—Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+724/12/202517/6/2026
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
AplazadaAlta (8.8)0.35%💥 PoCKraftplugins Demo Importer PlusAI18/12/202517/6/2026
The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.1)0.21%—Wordplus Better MessagesAI17/12/202517/6/2026
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display name in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaMedia (4.3)0.44%—Zohocorp Manageengine Admanager Plus15/12/20257/10/2026
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
AplazadaMedia (5.3)0.28%—Filter PlusAI12/12/202517/6/2026
The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.1.6 due to a missing capability check on the 'filter_save_settings' and 'add_filter_options' AJAX actions. This makes it…
AnalizadaCrítica (9.9)0.72%—Sandboxie-plus Sandboxie11/12/202517/6/2026
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt to sandboxed processes. The handler adds a fixed header size to a caller-controlled value_len without overflow…