Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Tuyennv TZ Plus GalleryAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery tz-plus-gallery allows Stored XSS.This issue affects TZ PlusGallery: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.5) | 0.45% | — | Beyaz Computer CityplusAI | 19/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal. This issue affects CityPlus: before 24.29375. | |
| Aplazada | Media (6.4) | 0.24% | — | Elements PlusAI | 11/9/2025 | 17/6/2026 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSpot Plus, and Google Maps widgets in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.4) | 0.24% | — | Element-plus | 9/9/2025 | 17/6/2026 | Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL… | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Officeplus | 9/9/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Baja (2.3) | 0.14% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived. | |
| Analizada | Alta (7.5) | 0.29% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station. | |
| Analizada | Baja (2.3) | 0.22% | — | Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+9 | 5/9/2025 | 17/6/2026 | ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. | |
| Aplazada | Alta (8.5) | 0.27% | — | Gopiplus NEW Simple GalleryAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Blind SQL Injection.This issue affects New Simple Gallery: from n/a through <= 8.0. | |
| Aplazada | Media (5.9) | 0.18% | — | Spiffyplugins WP Flow PlusAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.5. | |
| Aplazada | Baja (1.3) | 0.28% | — | Mupen64plusAI | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The… | |
| Aplazada | Crítica (9.3) | 1.3% | 💥 Exploit | Belkin Bulldog PlusAI | 30/8/2025 | 1/10/2026 | Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service authentication handler. When a specially crafted HTTP request is sent with an oversized Authorization header, the application fails to properly validate the input length before copying it into a… | |
| Aplazada | Media (5.3) | 0.24% | — | WC PlusAI | 23/8/2025 | 17/6/2026 | The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pluswc_logo_favicon_logo_base' AJAX action in all versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to update the site's favicon logo base. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Anji-plus Aj-reportAI | 22/8/2025 | 17/6/2026 | An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL. | |
| Aplazada | Media (5.3) | 0.24% | — | Reolink Smart 2K Plus Plug IN WI FI Video Doorbell With ChimeAI | 22/8/2025 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to access the Admin-only settings and edit the session storage. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Mupen64plusAI | 22/8/2025 | 17/6/2026 | In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, which enables executing arbitrary commands on the host machine. | |
| Aplazada | Alta (8.1) | 0.27% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Aplazada | Media (6.5) | 0.20% | — | Beplusthemes AloneAI | 20/8/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through < 7.8.5. | |
| Aplazada | Media (5.3) | 0.21% | — | WP Discord Post PlusAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2. | |
| Aplazada | Baja (1.9) | 0.17% | — | Elseplus File Recovery APPAI | 18/8/2025 | 17/6/2026 | A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to… | |
| Aplazada | Alta (8.8) | 0.42% | — | Gopiplus Vertical Scroll Slideshow GalleryAI | 15/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blind SQL Injection. This issue affects Vertical scroll slideshow gallery v2: from n/a through 9.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Theplus THE Plus Addons FOR Elementor Page BuilderAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.3.13. | |
| Modificada | Media (6.3) | 0.41% | — | F5 Nginx PlusF5 Nginx Open Source | 13/8/2025 | 17/6/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX… | |
| Aplazada | Crítica (9.3) | 0.78% | 💥 PoC | Instar 2K PlusAIInstar 4KAI | 13/8/2025 | 17/6/2026 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpexpertdeveloper WP Private Content PlusAI | 12/8/2025 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and… |