Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.9% | 💥 PoC | Dynatrace Activegate Ping Extension | 5/11/2025 | 17/6/2026 | OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. | |
| Aplazada | Media (4.3) | 0.23% | — | Qodeinteractive QI BlocksAI | 1/11/2025 | 17/6/2026 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without proper sanitization in the `update_global_styles_callback()` function.… | |
| Aplazada | Media (6.4) | 0.24% | — | Inactive LogoutAI | 1/11/2025 | 17/6/2026 | The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (8.4) | 0.20% | — | Microsoft Active DirectoryAI | 31/10/2025 | 7/10/2026 | When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality. | |
| Modificada | Media (5.4) | 0.12% | — | Qodeinteractive Bard | 31/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6. | |
| Modificada | Media (4.3) | 0.17% | — | Jenkins Byteguard Build Actions | 29/10/2025 | 17/6/2026 | Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.17% | — | Jenkins Byteguard Build Actions | 29/10/2025 | 17/6/2026 | Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system. | |
| Aplazada | Media (6.5) | 0.20% | — | Buddydev Activity Plus ReloadedAIBuddypressAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Stored XSS.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Arevico WP Tactical PopupAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Tactical Popup wp-tactical-popup allows Reflected XSS.This issue affects WP Tactical Popup: from n/a through <= 1.1. | |
| Modificada | Crítica (9.8) | 2.1% | — | Apache Activemq NMS Amqp | 16/10/2025 | 17/6/2026 | A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the… | |
| Aplazada | Alta (8.8) | 0.80% | — | System Security Services Daemon SssdAIMicrosoft Active DirectoryAIMIT KerberosAI | 9/10/2025 | 31/8/2026 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with… | |
| Aplazada | Media (5.5) | 0.22% | — | Interactive Human Anatomy With Clickable Body PartsAI | 3/10/2025 | 17/6/2026 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (7.7) | 1.5% | — | Sonarqube Github ActionAI | 26/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper… | |
| Aplazada | Alta (7.1) | 0.13% | — | Loopus WP Attractive Donations SystemAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-easy-stripe-paypal-donations allows Stored XSS.This issue affects WP Attractive Donations System: from n/a through < 1.29. | |
| Aplazada | Media (6.5) | 0.16% | — | Damian BP BP Disable Activation ReloadedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Damian BP Disable Activation Reloaded bp-disable-activation-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Disable Activation Reloaded: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.4) | 0.28% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Aplazada | Baja (1.9) | 0.13% | — | Apeuni PTE Exam Practice APPAI | 19/9/2025 | 17/6/2026 | A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the component com.ape_edication. The manipulation results in improper export of android application components. The attack requires a local… | |
| Aplazada | Crítica (9.8) | 0.44% | 💥 PoC | BGS Interactive Sinav.linkAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection. This issue affects SINAV.LINK Exam Result Module: before 1.2. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Interactive-git-checkoutAI | 9/9/2025 | 17/6/2026 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the command-line. It is available as an npm package and can be installed via `npm install -g interactive-git-checkout`. Versions up to and including 1.1.4 of… | |
| Analizada | Alta (8.7) | 0.37% | — | Rockwellautomation Factorytalk Activation Manager | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise. | |
| Aplazada | Media (5.9) | 0.22% | — | Properfraction MailoptinAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin mailoptin allows Stored XSS.This issue affects MailOptin: from n/a through <= 1.2.75.0. | |
| Aplazada | Alta (7.8) | 1.1% | — | Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI | 2/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to… | |
| Aplazada | Alta (7.5) | 1.1% | 💥 Exploit | Activepdf WebgrabberAI | 30/8/2025 | 16/6/2026 | activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not… | |
| Analizada | Alta (8.7) | 2.0% | 💥 Exploit | Cacti | 30/8/2025 | 23/9/2026 | Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the… |