Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 2.3% | 💥 Exploit | Amidaware Tactical RMM | 29/1/2026 | 17/6/2026 | A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs… | |
| Aplazada | Media (5.4) | 0.22% | — | CactiAI | 29/1/2026 | 17/6/2026 | A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements (e.g., <h1>, <b>,… | |
| Aplazada | Alta (8.8) | 0.52% | — | Amidaware Tactical RMMAI | 28/1/2026 | 17/6/2026 | An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creation of a new agent via the POST /api/v3/newagent/ endpoint. The agent_id parameter accepts up to 255 characters and is improperly sanitized using… | |
| Aplazada | Media (6.4) | 0.24% | — | InteractionsAI | 28/1/2026 | 17/6/2026 | The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event selectors in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.30% | — | Solwininfotech User Activity LOGAI | 28/1/2026 | 17/6/2026 | The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off) | |
| Aplazada | Media (4.3) | 0.41% | — | Hibernate ReactiveAI | 26/1/2026 | 17/6/2026 | A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available… | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Aplazada | Media (4.3) | 0.26% | — | Qodeinteractive WanderlandAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5. | |
| Aplazada | Media (5.4) | 0.27% | — | Qodeinteractive CurlyAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3. | |
| Aplazada | Alta (8.1) | 0.39% | — | Booking ActivitiesAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Booking Activities: from n/a through <= 1.16.44. | |
| Aplazada | Alta (8.1) | 0.59% | — | Qodeinteractive PowerliftAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Aplazada | Media (4.3) | 0.30% | — | Qodeinteractive BardAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229. | |
| Aplazada | Alta (7.1) | 0.28% | — | Highwarden Super Interactive MapsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Interactive Maps super-interactive-maps allows Reflected XSS.This issue affects Super Interactive Maps: from n/a through <= 2.3. | |
| Aplazada | Alta (8.5) | 0.15% | — | Luidia Ebeam Interactive SuiteAI | 21/1/2026 | 17/6/2026 | eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Luidia\eBeam Stylus Driver\ to inject malicious executables that… | |
| Aplazada | Alta (8.5) | 0.15% | — | ActividentityAI | 21/1/2026 | 17/6/2026 | ActivIdentity 8.2 contains an unquoted service path vulnerability in the ac.sharedstore service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\Common Files\ActivIdentity\ to inject malicious executables and escalate privileges. | |
| Aplazada | Baja (2.6) | 0.22% | — | Bestpractical Request TrackerAI | 16/1/2026 | 17/6/2026 | Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used. | |
| Analizada | Alta (8.5) | 0.23% | — | Pysoft Active Webcam | 16/1/2026 | 17/6/2026 | Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Hendon | 8/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP Local File Inclusion.This issue affects Hendon: from n/a through < 1.7. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Curly | 8/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.This issue affects Curly: from n/a through < 3.3. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Optimize | 8/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Wellspring | 8/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring allows PHP Local File Inclusion.This issue affects Wellspring: from n/a through < 2.8. | |
| Aplazada | Alta (7.5) | 0.42% | — | Loopus WP Attractive Donations SystemAI | 8/1/2026 | 7/10/2026 | Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Aplazada | Media (4.3) | 0.14% | — | Sticky Action ButtonsAI | 7/1/2026 | 17/6/2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the sabs_options_page_form_submit() function. This makes it possible for unauthenticated attackers to update plugin settings via… | |
| Aplazada | Alta (7.5) | 0.36% | — | Solwininfotech User Activity LOGAI | 7/1/2026 | 17/6/2026 | The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push… | |
| Aplazada | Media (6.5) | 0.17% | — | Buddydev Buddypress Activity ShortcodeAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Activity Shortcode bp-activity-shortcode allows Stored XSS.This issue affects BuddyPress Activity Shortcode: from n/a through <= 1.1.8. |