Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1221 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.32% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (5.4) | 0.34% | — | Awesomemotive Easy Digital Downloads | 29/5/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Crítica (9.8) | 0.51% | — | Digitalzoomstudio Zoomsounds | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91. | |
| Analizada | Media (5.4) | 0.18% | — | Westerndeal Easy Digital Downloads Google Sheet ConnectorEDD Gsheetconnector | 15/5/2025 | 17/6/2026 | The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Aplazada | Alta (7.8) | 0.22% | — | GEN Digital Avast Cleanup PremiumAI | 9/5/2025 | 17/6/2026 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU… | |
| Analizada | Media (6.9) | 3.8% | 💥 Exploit | Liferay Digital Experience PlatformLiferay Portal | 6/5/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject… | |
| Aplazada | Baja (2.1) | 0.22% | — | Opentext Digital Asset ManagementAI | 28/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4. | |
| Aplazada | Alta (7.5) | 0.91% | — | Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+8 | 25/4/2025 | 27/8/2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with… | |
| Analizada | Media (6.1) | 0.34% | — | Digitaldruid Hoteldruid | 22/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter. | |
| Aplazada | Alta (7.1) | 0.29% | — | Poppinsdigital Wpyog DocumentsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PoppinsDigital.com WPYog Documents wpyog-documents allows Reflected XSS.This issue affects WPYog Documents: from n/a through <= 1.3.5. | |
| Analizada | Media (4.8) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 17/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through… | |
| Aplazada | Alta (7.1) | 0.19% | — | Vsourz Digital WP MAP Route PlannerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital WP Map Route Planner wp-map-route-planner allows Cross Site Request Forgery.This issue affects WP Map Route Planner: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.38% | — | Hivedigital Canonical AttachmentsAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8. | |
| Aplazada | Media (5.3) | 0.51% | — | Asylumdigital AGE GateAI | 9/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4. | |
| Analizada | Alta (7.5) | 0.40% | — | Digitalzoomstudio Zoomsounds | 8/4/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Media (5.4) | 0.23% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions… | |
| Analizada | Alta (8.1) | 0.35% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.24% | — | Hutsixdigital TigerAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0. | |
| Aplazada | Alta (7.1) | 0.31% | — | Madfishdigital Bulk Noindex Nofollow ToolkitAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit bulk-noindex-nofollow-toolkit-by-mad-fish allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through <= 2.16. | |
| Aplazada | Media (6.5) | 0.36% | — | Digitalcourt Marketer AddonsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons marketer-addons allows Stored XSS.This issue affects Marketer Addons: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.9) | 20% | — | Digital China Dcme-520AI | 31/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack… | |
| Aplazada | Media (6.1) | 0.33% | — | Digital License ManagerAI | 25/3/2025 | 17/6/2026 | The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (5.3) | 0.39% | — | Awesomemotive Easy Digital Downloads | 25/3/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post… | |
| Analizada | Media (5.1) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 20/3/2025 | 17/6/2026 | The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms. | |
| Aplazada | Media (5.9) | 0.29% | — | HCL Digital ExperienceAIHCL Ring APIAIHCL DxclientAI | 20/3/2025 | 17/6/2026 | HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties. |