Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.8%—UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+282/7/202610/7/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
AnalizadaAlta (8.8)0.43%—UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+282/7/202610/7/2026
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
AplazadaCrítica (9.8)0.56%—Novalnet Payment GatewayAI2/7/20262/7/2026
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
AplazadaAlta (7.2)0.43%—Algoritmika Custom Payment Gateways FOR WoocommerceAI1/7/20261/7/2026
The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (8.8)0.63%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
AnalizadaAlta (8.8)1.0%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/202627/8/2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AnalizadaAlta (8.8)0.50%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
AnalizadaAlta (8.7)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaMedia (6.9)0.56%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaAlta (7.1)0.58%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
AplazadaMedia (6.5)0.17%—Funnelkit Payment Gateway FOR Stripe WoocommerceAI26/6/202629/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
AplazadaMedia (6.5)0.33%—Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.5)0.43%—Corvuspay Woocommerce Payment GatewayAI26/6/202626/6/2026
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
AplazadaMedia (5.4)0.29%—UPI QR Code Payment GatewayAI25/6/202625/6/2026
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
AplazadaAlta (7.1)0.40%—Openharness Ohmo GatewayAI23/6/202624/6/2026
OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote senders to enumerate and load arbitrary session snapshots by ID. Attackers can exploit this to access victim snapshots containing private prompts, credentials, tool output, and file paths via shared…
AnalizadaAlta (8.6)0.46%—F5 Nginx Gateway Fabric17/6/202622/6/2026
When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are…
AnalizadaAlta (7.1)0.50%—F5 Nginx Gateway Fabric17/6/20262/7/2026
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which…
AnalizadaMedia (6.3)0.37%—F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+317/6/202611/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction…
ModificadaCrítica (9.2)1.1%💥 PoCF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source17/6/202616/7/2026
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a…
ModificadaCrítica (9.2)6.5%💥 PoCF5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+717/6/202614/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the…
AnalizadaAlta (8.6)0.57%—F5 Nginx Gateway Fabric17/6/20262/7/2026
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource…
AplazadaMedia (6.5)0.40%—Woocommerce Stripe Payment GatewayAI16/6/202617/6/2026
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment…
AplazadaAlta (7.5)0.42%—Conekta Payment GatewayAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
AplazadaAlta (7.5)0.42%—Idpay Payment GatewayAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
AnalizadaAlta (8.6)0.22%—Vmware Spring Cloud Gateway15/6/20261/10/2026
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway…
Orbitaley — Vulnerabilidades