Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.20%—Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+1211/11/202517/6/2026
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo…
AplazadaAlta (8.6)0.35%—Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+1211/11/202517/6/2026
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo…
AplazadaCrítica (9.8)1.7%—Zohocorp Manageengine Analytics PlusAI11/11/202517/6/2026
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
AnalizadaMedia (6.1)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
AnalizadaMedia (5.4)0.49%—Zohocorp Manageengine Exchange Reporter Plus11/11/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
AplazadaCrítica (9.3)0.52%—Hundredplus EIP PlusAI10/11/202517/6/2026
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
AplazadaAlta (8.6)0.63%—Hundredplus EIP PlusAI10/11/20257/10/2026
EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaBaja (2.1)0.55%—Gztozed ZLT T10 Plus Firmware9/11/202517/6/2026
A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. Such manipulation leads to denial of service. Access to the local network is required for this attack to succeed. The exploit is publicly…
AplazadaBaja (2.9)0.46%—Newbee-ltd Newbee-mall-plusAI7/11/202517/6/2026
A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid leads to authorization bypass. It is possible to initiate the attack remotely. The attack is considered to have high complexity.…
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.
AnalizadaMedia (5.4)0.45%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.
AnalizadaMedia (6.5)1.1%—Zohocorp Manageengine Exchange Reporter Plus30/10/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.
AplazadaBaja (2.1)0.26%—Dulaiduwang003 Time-sea-plusAI27/10/202517/6/2026
A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible.…
AplazadaMedia (6.5)0.20%—Buddydev Activity Plus ReloadedAIBuddypressAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Stored XSS.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
AplazadaMedia (6.5)0.26%—Simpledns Simple DNS PlusAI24/10/202517/6/2026
Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server to return request payloads from other clients. This happens when the TCP length prefix is malformed (len differs from actual packet len), and due to a concurrency/buffering issue,…
AplazadaAlta (7.1)0.25%—G5theme Grid PlusAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Grid Plus grid-plus allows Reflected XSS.This issue affects Grid Plus: from n/a through <= 3.3.
AplazadaAlta (7.1)0.25%—Webjunk Calendar PlusAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webjunk Calendar Plus calendar-plus allows Reflected XSS.This issue affects Calendar Plus: from n/a through <= 1.2.4.
AplazadaCrítica (10)0.53%—Beplusthemes AloneAI22/10/20255/10/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through <= 7.8.3.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Admanager Plus21/10/202517/6/2026
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
AplazadaAlta (8.2)0.28%—Beyaz Bilgisayar CityplusAI21/10/202530/9/2026
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus allows Detect Unpublicized Web Pages. This issue affects CityPLus: before V24.29500.1.0.
AnalizadaAlta (8.8)27%—Zohocorp Manageengine Analytics Plus21/10/202517/6/2026
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
AplazadaCrítica (9.3)0.53%—Siemens Simatic CP 1542sp-1AISiemens Simatic CP 1542sp-1 IRCAISiemens Simatic CP 1543sp-1AISiemens Siplus ET 200sp CP 1542sp-1 IRC TX RailAI+214/10/202517/6/2026
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions…
AplazadaMedia (6.5)0.30%💥 PoCWpexpertdeveloper WP Private Content PlusAI13/10/202517/6/2026
The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually…