Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.39% | — | Qodeinteractive Lekker | 30/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8. | |
| Modificada | Media (5.4) | 0.22% | — | Qodeinteractive Fivestar | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiveStar: from n/a through <= 1.7. | |
| Modificada | Media (5.4) | 0.22% | — | Qodeinteractive Backpack Traveler | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3. | |
| Analizada | Baja (2.9) | 0.62% | — | Actionsky Sqle | 27/12/2025 | 7/10/2026 | A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret Handler. The manipulation of the argument JWTSecretKey leads to use of hard-coded cryptographic key . The attack is possible to be carried… | |
| Aplazada | Media (6.5) | 0.17% | — | Creativeinteractivemedia Real3d-flipbook-liteAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Tacticool | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tacticool tacticool allows PHP Local File Inclusion.This issue affects Tacticool: from n/a through <= 1.0.13. | |
| Aplazada | Media (4.3) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 16/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Cross Site Request Forgery.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25. | |
| Modificada | Alta (8.8) | 0.45% | — | Qodeinteractive Wilmer | 9/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.5. | |
| Modificada | Media (4.3) | 0.28% | — | Qodeinteractive Powerlift | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Aplazada | Media (4.3) | 0.38% | — | Marcoingraiti Actionwear-products-syncAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Actionwear products sync: from n/a through <= 2.3.3. | |
| Analizada | Alta (7.4) | 11% | — | Cacti | 2/12/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored… | |
| Modificada | Media (6.1) | 0.20% | — | Datateam Datactive | 2/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Datateam Information Technologies Inc. Datactive allows Stored XSS. This issue affects Datactive: from 2.13.34 before 2.14.0.6. | |
| Analizada | Crítica (9.8) | 0.68% | — | Owasp Faction | 26/11/2025 | 17/6/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the server when a lifecycle hook is invoked, resulting in remote code execution (RCE) on… | |
| Analizada | Alta (8.7) | 2.8% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateLicense.php. When a license file is uploaded, the application derives a new filename by combining a… | |
| Analizada | Alta (8.7) | 3.4% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php. When a fax "send" test is requested, the application builds a faxsender command line using… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through… | |
| Analizada | Alta (8.7) | 0.53% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism that lacks access control, allowing remote, unauthenticated users to request files stored on the… | |
| Analizada | Media (6.9) | 0.46% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the… | |
| Analizada | Crítica (9.3) | 1.1% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it… | |
| Analizada | Crítica (9.3) | 0.71% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action writes attacker-supplied data directly to… | |
| Aplazada | Media (4.3) | 0.22% | — | Qodeinteractive QI BlocksAI | 15/11/2025 | 7/10/2026 | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it… | |
| Aplazada | Media (6.5) | 0.16% | — | Qodeinteractive QI BlocksAI | 13/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through <= 1.4.3. | |
| Modificada | Alta (8.1) | 0.61% | — | Qodeinteractive Wanderland | 6/11/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1. | |
| Modificada | Alta (8.1) | 0.67% | — | Qodeinteractive DOR | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4. |