Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

3977 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.49%—Basixonline Nex-formsAI27/6/202629/6/2026
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate…
AplazadaMedia (5.3)0.50%—Getoutline OutlineAI25/6/202626/6/2026
Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth token has the required scopes for a request. It extracts the resource by splitting the URL by / and taking the last segment. However, it…
AnalizadaMedia (4.3)0.34%—Jenkins Pipeline\24/6/202626/6/2026
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.
AnalizadaMedia (4.3)0.24%—Jenkins Pipeline\24/6/202626/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.
AplazadaAlta (8.7)0.33%—Safeline SL6AISafeline Sl6+AI22/6/20266/10/2026
The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an…
AplazadaCrítica (9.4)0.23%—Line Centraldogma-serverAIApache ZookeeperAI22/6/202622/6/2026
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an…
AnalizadaCrítica (9.6)0.69%—Microsoft Exchange Online19/6/202624/6/2026
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (8.8)0.56%—Line Desktop MCPAI19/6/202623/6/2026
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to…
AplazadaMedia (5.9)0.32%—Line Armeria-xdsAI19/6/202622/6/2026
A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local files and environment…
AplazadaAlta (8.1)0.35%—Line AgencyAI17/6/20266/10/2026
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
AplazadaMedia (6.5)0.27%—Ali2woo AlinextAI17/6/20261/10/2026
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.
AplazadaMedia (4.3)0.12%—Extendthemes Skyline WPAI17/6/20261/10/2026
Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.
AplazadaCrítica (9.9)0.48%—Themagnifico52 Kids Online StoreAI16/6/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaMedia (4.3)0.76%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.2)0.60%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7)0.28%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AplazadaMedia (6.5)0.19%—OfflineimapAI8/6/202623/7/2026
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.
AplazadaMedia (5.5)0.29%—Code-projects Online Music SiteAI8/6/202623/7/2026
A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.5)0.27%—Code-projects Online Music SiteAI8/6/202623/7/2026
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AplazadaCrítica (9.8)0.64%💥 PoCDTS Electronics Industry AND Trade LTD Redline Wr3200AI5/6/202623/7/2026
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
AnalizadaAlta (7.5)1.00%—Microsoft Exchange Online4/6/202623/7/2026
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.