Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
3977 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.49% | — | Basixonline Nex-formsAI | 27/6/2026 | 29/6/2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate… | |
| Aplazada | Media (5.3) | 0.50% | — | Getoutline OutlineAI | 25/6/2026 | 26/6/2026 | Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the required scopes for a request. It extracts the resource by splitting the URL by / and taking the last segment. However, it… | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins Pipeline\ | 24/6/2026 | 26/6/2026 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps. | |
| Analizada | Media (4.3) | 0.24% | — | Jenkins Pipeline\ | 24/6/2026 | 26/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator. | |
| Aplazada | Alta (8.7) | 0.33% | — | Safeline SL6AISafeline Sl6+AI | 22/6/2026 | 6/10/2026 | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an… | |
| Aplazada | Crítica (9.4) | 0.23% | — | Line Centraldogma-serverAIApache ZookeeperAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an… | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Exchange Online | 19/6/2026 | 24/6/2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.8) | 0.56% | — | Line Desktop MCPAI | 19/6/2026 | 23/6/2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to… | |
| Aplazada | Media (5.9) | 0.32% | — | Line Armeria-xdsAI | 19/6/2026 | 22/6/2026 | A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local files and environment… | |
| Aplazada | Alta (8.1) | 0.35% | — | Line AgencyAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Ali2woo AlinextAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5. | |
| Aplazada | Media (4.3) | 0.12% | — | Extendthemes Skyline WPAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Themagnifico52 Kids Online StoreAI | 16/6/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.3) | 0.76% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.2) | 0.60% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7) | 0.28% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.5) | 0.19% | — | OfflineimapAI | 8/6/2026 | 23/7/2026 | OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext. | |
| Aplazada | Media (5.5) | 0.29% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | DTS Electronics Industry AND Trade LTD Redline Wr3200AI | 5/6/2026 | 23/7/2026 | Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8. | |
| Analizada | Alta (7.5) | 1.00% | — | Microsoft Exchange Online | 4/6/2026 | 23/7/2026 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. |