Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1221 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 4.9% | 💥 Exploit | Asylumdigital AGE GateAI | 20/3/2025 | 17/6/2026 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be… | |
| Analizada | Media (5.1) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 19/3/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's… | |
| Aplazada | Crítica (9.1) | 0.91% | 💥 PoC | Dorset DG 201 Digital LockAI | 17/3/2025 | 17/6/2026 | An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication. | |
| Analizada | Alta (7.1) | 0.65% | 💥 PoC | Digitaldruid Hoteldruid | 11/3/2025 | 17/6/2026 | An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies. | |
| Analizada | Alta (7.3) | 0.42% | 💥 PoC | Digitaldruid Hoteldruid | 11/3/2025 | 17/6/2026 | A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is… | |
| Analizada | Media (5.4) | 0.55% | 💥 PoC | Digitaldruid Hoteldruid | 11/3/2025 | 17/6/2026 | Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint | |
| Analizada | Media (6.9) | 0.60% | — | Caishixiong Modern Farm Digital Integrated Management System | 10/3/2025 | 17/6/2026 | A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.64% | — | Digitalzoomstudio Zoomsounds | 5/3/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (6.5) | 0.35% | — | Digitalzoomstudio DZS Ajaxer LiteAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: from n/a through <= 1.04. | |
| Analizada | Alta (8.8) | 0.51% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Alta (8.8) | 0.52% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells | |
| Analizada | Crítica (9.8) | 0.58% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. | |
| Aplazada | Crítica (9.8) | 0.94% | — | Digital China Dcbi-netlog-lab GatewayAI | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Aplazada | Media (5.1) | 0.25% | — | Digital China Dcbc Gateway 200AI | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Modificada | Media (6.1) | 0.15% | — | Blackandwhitedigital Bookpress | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. | |
| Modificada | Crítica (9.8) | 0.47% | — | Blackandwhitedigital Bookpress | 7/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. | |
| Aplazada | Media (6.5) | 0.29% | — | Digitalzoomstudio Demo User DZSAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Demo User DZS demo-user-dzs-showcase-your-admin-safely allows Stored XSS.This issue affects Demo User DZS: from n/a through <= 1.1.0. | |
| Analizada | Media (4) | 0.24% | — | Awesomemotive Easy Digital Downloads | 18/1/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.20% | — | Digitalfisherman Geotagged-mediaAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitalfisherman Geotagged Media geotagged-media allows Stored XSS.This issue affects Geotagged Media: from n/a through <= 0.3.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Digitaldonkey Multilang Contact FormAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Reflected XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpecommerce Sell Digital DownloadsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Sell Digital Downloads sell-digital-downloads allows Stored XSS.This issue affects Sell Digital Downloads: from n/a through <= 2.2.7. | |
| Aplazada | Media (4.3) | 0.20% | — | Digitalzoomstudio Admin Debug Wordpress Enable DebugAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13. | |
| Analizada | Media (4.9) | 0.99% | — | Awesomemotive Easy Digital Downloads | 21/12/2024 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to read… | |
| Analizada | Media (4.8) | 0.28% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into… | |
| Modificada | Media (4.6) | 0.34% | — | Liferay PortalLiferay Digital Experience Platform | 17/12/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field |