Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2154 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Novalnet Payment GatewayAI | 2/7/2026 | 2/7/2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | Algoritmika Custom Payment Gateways FOR WoocommerceAI | 1/7/2026 | 1/7/2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.8) | 0.63% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment | |
| Analizada | Alta (8.8) | 1.0% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 27/8/2026 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server | |
| Analizada | Alta (8.8) | 0.50% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | |
| Analizada | Alta (8.7) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Media (6.9) | 0.56% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Alta (7.1) | 0.58% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | |
| Aplazada | Media (6.5) | 0.17% | — | Funnelkit Payment Gateway FOR Stripe WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Corvuspay Woocommerce Payment GatewayAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | UPI QR Code Payment GatewayAI | 25/6/2026 | 25/6/2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | Openharness Ohmo GatewayAI | 23/6/2026 | 24/6/2026 | OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared… | |
| Analizada | Alta (8.6) | 0.46% | — | F5 Nginx Gateway Fabric | 17/6/2026 | 22/6/2026 | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are… | |
| Analizada | Alta (7.1) | 0.50% | — | F5 Nginx Gateway Fabric | 17/6/2026 | 2/7/2026 | When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which… | |
| Analizada | Media (6.3) | 0.37% | — | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+3 | 17/6/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction… | |
| Modificada | Crítica (9.2) | 1.1% | 💥 PoC | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source | 17/6/2026 | 16/7/2026 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Analizada | Alta (8.6) | 0.57% | — | F5 Nginx Gateway Fabric | 17/6/2026 | 2/7/2026 | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource… | |
| Aplazada | Media (6.5) | 0.40% | — | Woocommerce Stripe Payment GatewayAI | 16/6/2026 | 17/6/2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment… | |
| Aplazada | Alta (7.5) | 0.42% | — | Conekta Payment GatewayAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Idpay Payment GatewayAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions. | |
| Analizada | Alta (8.6) | 0.22% | — | Vmware Spring Cloud Gateway | 15/6/2026 | 1/10/2026 | Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway… |