Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.2% | 💥 Exploit | Dynamiapps Frontend AdminAI | 3/12/2025 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.46% | — | Dcatadmin Dcat Admin | 2/12/2025 | 17/6/2026 | dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. | |
| Analizada | Alta (8.7) | 0.58% | — | Gin-vue-admin Project Gin-vue-admin | 1/12/2025 | 17/6/2026 | Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder. | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.2) | 0.23% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.8) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/site endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/groups/Grupo endpoint of the Grav application. This vulnerability… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (5.3) | 0.32% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Forgot Password" functionality at /admin/forgot leaks information about valid… | |
| Aplazada | Media (6.1) | 0.21% | — | Echbay Admin SecurityAI | 21/11/2025 | 7/10/2026 | The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.21% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper validation or access control checks.… | |
| Analizada | Media (6.5) | 0.29% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper sanitization. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL… | |
| Analizada | Media (6.5) | 0.27% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authenticated attacker can… | |
| Analizada | Media (6.1) | 0.23% | — | Phppgadmin Project Phppgadmin | 20/11/2025 | 17/6/2026 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or sanitization in multiple locations including sequences.php, indexes.php, admin.php, and other… | |
| Aplazada | Media (5.3) | 0.23% | — | Xwiki AdmintoolsAI | 18/11/2025 | 17/6/2026 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still… | |
| Aplazada | Media (4.3) | 0.12% | — | WP Admin MicroblogAI | 18/11/2025 | 17/6/2026 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf of an administrator… | |
| Modificada | Crítica (9.8) | 13% | 💥 PoC | Pgadmin 4 | 13/11/2025 | 17/6/2026 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the… | |
| Analizada | Alta (7.4) | 0.22% | — | Pgadmin 4 | 13/11/2025 | 7/10/2026 | pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification. | |
| Analizada | Alta (7.5) | 0.45% | — | Pgadmin 4 | 13/11/2025 | 7/10/2026 | pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS. | |
| Modificada | Alta (8.8) | 0.94% | — | Pgadmin 4 | 13/11/2025 | 7/10/2026 | pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input. | |
| Aplazada | Media (4.3) | 0.12% | — | WP Custom Admin Login Page LogoAI | 11/11/2025 | 7/10/2026 | The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings… | |
| Aplazada | Media (5.4) | 0.22% | — | MDZ Persian Admin FontsAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Persian Admnin Fonts: from n/a through <= 4.1.03. | |
| Aplazada | Media (5.5) | 0.20% | — | Wpseek Admin Management XtendedAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin Management Xtended : from n/a through <= 2.5.1. | |
| Analizada | Alta (8.2) | 0.36% | — | Directadmin | 3/10/2025 | 17/6/2026 | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request. | |
| Aplazada | Media (5.9) | 0.18% | — | Kontur Admin StyleAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur.us kontur Admin Style kontur-admin-style allows Stored XSS.This issue affects kontur Admin Style: from n/a through <= 1.0.4. |