Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.62% | — | Minio OperatorAI | 22/4/2025 | 17/6/2026 | MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been… | |
| Aplazada | Media (4.9) | 0.69% | — | QUY LE 91 Administrator ZAI | 16/4/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Quý Lê 91 Administrator Z administrator-z allows Path Traversal.This issue affects Administrator Z: from n/a through <= 2025.03.28. | |
| Aplazada | Media (5.4) | 0.51% | — | Miniorange Wordpress Rest API AuthenticationAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3. | |
| Aplazada | Alta (8.8) | 0.37% | — | QUY LE 91 Administrator ZAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a through <= 2025.03.24. | |
| Aplazada | Media (4.3) | 0.15% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request Forgery.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Aplazada | Media (6.5) | 0.40% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quý Lê 91 Administrator Z administrator-z allows DOM-Based XSS.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Aplazada | Alta (8.7) | 2.5% | 💥 Exploit | MinioAI | 3/4/2025 | 17/6/2026 | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on the bucket. Prior… | |
| Aplazada | Media (4.8) | 0.42% | — | MinifluxAI | 3/4/2025 | 17/6/2026 | Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy has been changed from default-src… | |
| Aplazada | Media (6.4) | 0.34% | — | Manuel Schmalstieg Minimalistic Event ManagerAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Manuel Schmalstieg Minimalistic Event Manager minimalistic-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimalistic Event Manager: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Agency Dominion INC FusionAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion allows DOM-Based XSS.This issue affects Fusion: from n/a through <= 1.6.4. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login. | |
| Aplazada | Media (4.6) | 0.31% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can access the microSD card used on the product may obtain the product login password. | |
| Aplazada | Alta (7.5) | 0.80% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attacker may obtain the product login password without authentication. | |
| Aplazada | Alta (8.8) | 0.36% | — | Administrator ZAI | 28/3/2025 | 17/6/2026 | The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminz_import_backup() function in all versions up to, and including, 2025.03.24. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.6) | 0.45% | — | Jiangqie Official Website Mini ProgramAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jiangqie JiangQie Official Website Mini Program jiangqie-official-website-mini-program allows Blind SQL Injection.This issue affects JiangQie Official Website Mini Program: from n/a through <= 1.8.2. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Thememove MinimogwpAI | 19/3/2025 | 17/6/2026 | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the… | |
| Analizada | Alta (8.8) | 1.9% | 💥 Exploit | Geminilabs Site Reviews | 19/3/2025 | 17/6/2026 | The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks | |
| Aplazada | Media (6.9) | 0.36% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’, ‘searchSpecialitiesPending’, ‘searchSpecialitiesLinked’,… | |
| Aplazada | Media (4.3) | 0.17% | — | Rest API TO MiniprogramAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram rest-api-to-miniprogram allows Cross Site Request Forgery.This issue affects REST API TO MiniProgram: from n/a through <= 5.1.2. | |
| Analizada | Crítica (9.8) | 0.47% | — | Miniorange Social Login | 8/3/2025 | 17/6/2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.73% | — | Mackron Miniaudio | 4/3/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Media (4.8) | 0.38% | — | Projectteam Mini-tmall | 2/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown code of the file /admin of the component Admin Name Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (4.6) | 0.59% | — | MinioAI | 28/2/2025 | 17/6/2026 | MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09-55-16Z, a bug in evaluating the trust of the SSH key used in an SFTP connection to MinIO allows authentication bypass and unauthorized data access. On a MinIO server with SFTP access configured and… |