Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.73% | — | Contec CL4 6NX PlusAIContec CL4 6NX J PlusAI | 6/8/2025 | 17/6/2026 | CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege. | |
| Aplazada | Media (6.9) | 1.1% | — | Panasonic CL4 6NX PlusAIPanasonic CL4 6nx-j PlusAI | 6/8/2025 | 17/6/2026 | OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+345 | 6/8/2025 | 17/6/2026 | Information disclosure while processing the hash segment in an MBN file. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+338 | 6/8/2025 | 17/6/2026 | Information disclosure while reading data from an image using specified offset and size parameters. | |
| Aplazada | Media (6.4) | 0.24% | — | THE Plus AddonsAI | 1/8/2025 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html capability. This… | |
| Aplazada | Media (4.8) | 0.08% | — | Tsplus Remote AccessAI | 29/7/2025 | 17/6/2026 | Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables,… | |
| Analizada | Media (6.9) | 0.07% | — | Sandboxie-plus Sandboxie | 29/7/2025 | 17/6/2026 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, exposing them to… | |
| Aplazada | Media (6.1) | 0.21% | — | Affiliate PlusAI | 24/7/2025 | 17/6/2026 | The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'affiplus_settings' page. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can… | |
| Aplazada | Media (5.5) | 0.26% | — | Krasenslavov Featured Image PlusAI | 23/7/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.6 via the fip_get_image_options() function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web… | |
| Analizada | Baja (1.9) | 0.30% | — | Dunamu Stockplus | 20/7/2025 | 17/6/2026 | A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper export of android application components.… | |
| Aplazada | Baja (2.1) | 0.40% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. The manipulation of the argument Name leads to path traversal. The attack can be initiated remotely.… | |
| Aplazada | Baja (2.1) | 0.27% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The manipulation of the argument portraitFile leads to unrestricted upload. It is possible to initiate… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption while processing video packets received from video firmware. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+271 | 8/7/2025 | 17/6/2026 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+242 | 8/7/2025 | 17/6/2026 | Memory corruption while retrieving the CBOR data from TA. | |
| Analizada | Alta (8.2) | 0.22% | — | Qualcomm Sm6250 FirmwareQualcomm Sm6370 FirmwareQualcomm Sm7315 FirmwareQualcomm Sm7325p Firmware+175 | 8/7/2025 | 17/6/2026 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+217 | 8/7/2025 | 17/6/2026 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | |
| Analizada | Baja (2.9) | 0.81% | — | Mao888 Bluebell-plus | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the file bluebell_backend/pkg/jwt/jwt.go of the component JWT Token Handler. The manipulation of the argument mySecret with the input bluebell-plus leads to use of… | |
| Aplazada | Alta (7.2) | 0.23% | — | Beplusthemes AloneAI | 4/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects Alone: from n/a through <= 7.8.2. | |
| Aplazada | Media (6.5) | 0.28% | — | Gnuget MF Plus WpmlAI | 4/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MF Plus WPML: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.19% | — | Gopiplus Card Flip Image SlideshowAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip image slideshow card-flip-image-slideshow allows DOM-Based XSS.This issue affects Card flip image slideshow: from n/a through <= 1.5. | |
| Aplazada | Alta (8.5) | 0.29% | — | Gopiplus Pixelating Image Slideshow GalleryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelating image slideshow gallery pixelating-image-slideshow-gallery allows SQL Injection.This issue affects Pixelating image slideshow gallery: from n/a through <= 8.0. | |
| Aplazada | Alta (8.5) | 0.29% | — | Gopiplus Iframe Images GalleryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery wp-iframe-images-gallery allows SQL Injection.This issue affects iFrame Images Gallery: from n/a through <= 9.0. | |
| Aplazada | Alta (8.5) | 0.29% | — | Gopiplus Cool-fade-popupAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup cool-fade-popup allows Blind SQL Injection.This issue affects Cool fade popup: from n/a through <= 10.1. |