Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.97% | — | Viaviweb Wallpaper Admin | 13/1/2026 | 17/6/2026 | VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server. | |
| Analizada | Alta (8.8) | 0.70% | — | Viaviweb Wallpaper Admin | 13/1/2026 | 17/6/2026 | VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface. | |
| Analizada | Alta (7.5) | 0.23% | — | Microsoft Windows Admin Center | 13/1/2026 | 17/6/2026 | Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.3) | 1.1% | — | Gin-vue-admin Project Gin-vue-admin | 12/1/2026 | 17/6/2026 | Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile function accepts a fileName parameter through… | |
| Aplazada | Alta (7.2) | 0.29% | — | Dynamiapps Frontend AdminAI | 9/1/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.1) | 0.38% | — | Dynamiapps Frontend AdminAI | 9/1/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Crítica (9.8) | 0.72% | 💥 PoC | Dynamiapps Frontend AdminAI | 9/1/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.46% | — | Jackying H-ui.adminAI | 2/1/2026 | 17/6/2026 | A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/preview.php. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor… | |
| Aplazada | Media (4.3) | 0.24% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40. | |
| Analizada | Baja (1.9) | 0.28% | — | Youlai Vue3-element-admin | 31/12/2025 | 17/6/2026 | A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the component Notice Handler. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made… | |
| Modificada | Media (5.1) | 0.32% | — | Kyocera NET Admin | 24/12/2025 | 17/6/2026 | KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user… | |
| Analizada | Alta (7.1) | 0.90% | — | Kyocera NET Admin | 24/12/2025 | 17/6/2026 | KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database… | |
| Aplazada | Media (5.4) | 0.25% | — | Wpadminify WP AdminifyAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1. | |
| Aplazada | Media (4.3) | 0.23% | — | Wpadminify WP AdminifyAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1. | |
| Modificada | Baja (2) | 0.37% | — | Fastadmin | 19/12/2025 | 17/6/2026 | A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing a manipulation of the argument custom/searchField can lead to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.4) | 0.22% | — | Craigtaub Phpmsadmin | 18/12/2025 | 17/6/2026 | A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation. | |
| Modificada | Media (5.4) | 0.18% | — | Craigtaub Phpmsadmin | 18/12/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpexperts Protect WP AdminAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1. | |
| Aplazada | Baja (1.9) | 0.25% | — | Vion707 DmadminAI | 15/12/2025 | 7/10/2026 | A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the function Add of the file Admin/Controller/AddonsController.class.php of the component Backend. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.50% | — | Mineadmin | 12/12/2025 | 5/7/2026 | Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. | |
| Analizada | Alta (8.8) | 0.94% | 💥 PoC | Pgadmin 4 | 11/12/2025 | 7/10/2026 | pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Windows Admin Center | 11/12/2025 | 7/10/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Baja (2.7) | 0.29% | — | Wpase Admin AND Site EnhancementsAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | Custom Admin MenuAI | 9/12/2025 | 7/10/2026 | The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Baja (2.9) | 0.30% | — | Opsre Go-ldap-adminAI | 3/12/2025 | 17/6/2026 | A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secret key can lead to use of hard-coded cryptographic key . The attack can be… |