Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.55% | — | Friendsofshopware Froshadminer | 9/2/2026 | 17/6/2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. This vulnerability… | |
| Analizada | Media (5.5) | 2.4% | 💥 Exploit | Tpadmin Project Tpadmin | 7/2/2026 | 17/6/2026 | A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit… | |
| Modificada | Media (6.3) | 0.45% | — | Pgadmin 4 | 5/2/2026 | 17/6/2026 | pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in… | |
| Modificada | Media (6.5) | 0.21% | — | Eladmin | 4/2/2026 | 17/6/2026 | A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permission level. | |
| Analizada | Crítica (10) | 0.68% | — | Omran Fikir Odalari Adminpando | 3/2/2026 | 17/6/2026 | A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full administrative access to… | |
| Aplazada | Alta (7.5) | 0.70% | — | Chetans9 Core-php-admin-panelAI | 3/2/2026 | 17/6/2026 | chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_validate.php. The application sends an HTTP redirect via header(Location:login.php) when a user is not authenticated but fails to call exit() afterward. This allows remote unauthenticated attackers… | |
| Aplazada | Media (4.3) | 0.19% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41. | |
| Analizada | Alta (7.1) | 0.22% | — | Danofficeit Local Admin Service | 30/1/2026 | 17/6/2026 | Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpadminify WP AdminifyAI | 28/1/2026 | 17/6/2026 | The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/adminify/v1/get-addons-list REST API endpoint. The endpoint is registered with permission_callback set to __return_true, allowing unauthenticated attackers to retrieve the… | |
| Aplazada | Media (5.1) | 0.64% | — | Getgrav GravAIGetgrav Admin PluginAI | 26/1/2026 | 17/6/2026 | Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the… | |
| Aplazada | Media (4.6) | 0.17% | — | Kaba 9300 AdministrationAI | 26/1/2026 | 17/6/2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation. | |
| Aplazada | Media (4.3) | 0.18% | — | AdminquickbarAI | 24/1/2026 | 17/6/2026 | The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.3. This is due to missing or incorrect nonce validation on the 'saveSettings' and 'renamePost' AJAX actions. This makes it possible for unauthenticated attackers to modify plugin settings and… | |
| Aplazada | Alta (7.5) | 0.76% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' attribute of the 'get_template' shortcode. This is due to insufficient path validation on user-supplied input passed to the get_template_part() function. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'logout' shortcode attributes in all versions up to, and including, 0.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.21% | — | Jahid Hasan Admin Login URL ChangeAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Jahid Hasan Admin login URL Change admin-login-url-change allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin login URL Change: from n/a through <= 1.1.5. | |
| Aplazada | Alta (8.5) | 0.15% | — | Brother Bradmin ProfessionalAI | 21/1/2026 | 17/6/2026 | Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allows local users to potentially execute arbitrary code. Attackers can place a malicious executable named 'BRAdmin' in the C:\Program Files (x86)\Brother\ directory to gain local system privileges. | |
| Analizada | Baja (1.3) | 0.37% | — | Mineadmin | 20/1/2026 | 17/6/2026 | A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the file /system/downloadById. Performing a manipulation of the argument ID results in information disclosure. The attack can be initiated remotely. The attack's complexity is rated as high. The… | |
| Analizada | Baja (1.3) | 0.46% | — | Mineadmin | 20/1/2026 | 17/6/2026 | A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is… | |
| Analizada | Baja (1.3) | 0.25% | — | Mineadmin | 20/1/2026 | 17/6/2026 | A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high… | |
| Analizada | Media (5.5) | 0.78% | — | Mineadmin | 20/1/2026 | 17/6/2026 | A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about… | |
| Analizada | Baja (2.1) | 0.35% | — | Mineadmin | 19/1/2026 | 17/6/2026 | A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Baja (2.2) | 0.28% | — | Church AdminAI | 17/1/2026 | 17/6/2026 | The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.28 due to insufficient validation of user-supplied URLs in the 'audio_url' parameter. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to… | |
| Analizada | Media (4.3) | 0.36% | — | Pimcore Admin Classic Bundle | 15/1/2026 | 17/6/2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value)… | |
| Aplazada | Alta (8.5) | 0.19% | — | Contpaqi AdminpaqAI | 13/1/2026 | 17/6/2026 | CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during… | |
| Modificada | Alta (7.1) | 0.47% | — | Viaviweb Wallpaper Admin | 13/1/2026 | 17/6/2026 | VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information. |