Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.24%—Tuyennv TZ Plus GalleryAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery tz-plus-gallery allows Stored XSS.This issue affects TZ PlusGallery: from n/a through <= 1.5.5.
AplazadaAlta (7.5)0.45%—Beyaz Computer CityplusAI19/9/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal. This issue affects CityPlus: before 24.29375.
AplazadaMedia (6.4)0.24%—Elements PlusAI11/9/202517/6/2026
The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSpot Plus, and Google Maps widgets in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (6.4)0.24%—Element-plus9/9/202517/6/2026
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL…
AnalizadaAlta (7.5)1.1%—Microsoft Officeplus9/9/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.
AnalizadaBaja (2.3)0.14%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
AnalizadaAlta (7.5)0.29%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
AnalizadaBaja (2.3)0.22%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
AplazadaAlta (8.5)0.27%—Gopiplus NEW Simple GalleryAI5/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects New Simple Gallery: from n/a through <= 8.0.
AplazadaMedia (5.9)0.18%—Spiffyplugins WP Flow PlusAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.5.
AplazadaBaja (1.3)0.28%—Mupen64plusAI30/8/202517/6/2026
A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The…
AplazadaCrítica (9.3)1.3%💥 ExploitBelkin Bulldog PlusAI30/8/20251/10/2026
Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service authentication handler. When a specially crafted HTTP request is sent with an oversized Authorization header, the application fails to properly validate the input length before copying it into a…
AplazadaMedia (5.3)0.24%—WC PlusAI23/8/202517/6/2026
The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pluswc_logo_favicon_logo_base' AJAX action in all versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to update the site's favicon logo base.
AplazadaCrítica (9.8)0.80%—Anji-plus Aj-reportAI22/8/202517/6/2026
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.
AplazadaMedia (5.3)0.24%—Reolink Smart 2K Plus Plug IN WI FI Video Doorbell With ChimeAI22/8/202517/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to access the Admin-only settings and edit the session storage.
AplazadaCrítica (9.8)0.58%—Mupen64plusAI22/8/202517/6/2026
In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, which enables executing arbitrary commands on the host machine.
AplazadaAlta (8.1)0.27%—Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI20/8/202517/6/2026
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions…
AplazadaMedia (6.5)0.20%—Beplusthemes AloneAI20/8/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through < 7.8.5.
AplazadaMedia (5.3)0.21%—WP Discord Post PlusAI20/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.
AplazadaBaja (1.9)0.17%—Elseplus File Recovery APPAI18/8/202517/6/2026
A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to…
AplazadaAlta (8.8)0.42%—Gopiplus Vertical Scroll Slideshow GalleryAI15/8/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blind SQL Injection. This issue affects Vertical scroll slideshow gallery v2: from n/a through 9.1.
AplazadaMedia (6.5)0.23%—Theplus THE Plus Addons FOR Elementor Page BuilderAI14/8/202517/6/2026
Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.3.13.
ModificadaMedia (6.3)0.41%—F5 Nginx PlusF5 Nginx Open Source13/8/202517/6/2026
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX…
AplazadaCrítica (9.3)0.78%💥 PoCInstar 2K PlusAIInstar 4KAI13/8/202517/6/2026
A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.
AplazadaMedia (5.3)0.33%—Wpexpertdeveloper WP Private Content PlusAI12/8/202517/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and…