Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM Approve Timesheets FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Analizada | Baja (2) | 0.29% | — | Rems Personal Time Tracker | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (7.2) | 0.91% | 💥 PoC | Easy TimerAI | 4/9/2025 | 17/6/2026 | The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This is due to insufficient restriction of shortcode attributes. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. | |
| Aplazada | Alta (7.1) | 0.23% | — | Lambertgroup Multimedia Playlist Slider Addon FOR Wpbakery Page BuilderAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder:… | |
| Aplazada | Media (6.4) | 0.25% | — | Intl Datetime CalendarAI | 16/8/2025 | 17/6/2026 | The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.24% | — | Mrdenny Time SheetsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny Time Sheets time-sheets allows Reflected XSS.This issue affects Time Sheets: from n/a through <= 2.1.3. | |
| Aplazada | Alta (7.1) | 0.24% | — | Lambertgroup Multimedia Playlist Slider Addon FOR Wpbakery Page BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder lbg_vp_youtube_vimeo_addon_visual_composer allows Reflected XSS.This issue affects Multimedia Playlist Slider Addon for WPBakery Page Builder:… | |
| Aplazada | Alta (7.5) | 0.55% | — | Codesys Control RuntimeAI | 4/8/2025 | 17/6/2026 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition. | |
| Aplazada | Media (5.5) | 0.12% | — | Codesys Runtime ToolkitAI | 4/8/2025 | 17/6/2026 | CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions. | |
| Aplazada | Media (6.4) | 0.24% | 💥 PoC | Openplc RuntimeAI | 4/8/2025 | 17/6/2026 | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI. | |
| Aplazada | Media (6.1) | 0.21% | — | Codebangers ALL IN ONE Time Clock LiteAI | 2/8/2025 | 17/6/2026 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Media (6.5) | 0.49% | — | Iptime NAS Firmware | 30/7/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the unsafe use of the strcpy function to copy attacker-controlled data from the CONTENT_TYPE HTTP header into a fixed-size stack buffer (v8, allocated 8 bytes) without bounds checking.… | |
| Analizada | Media (6.9) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 29/7/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP… | |
| Aplazada | Media (5.3) | 0.29% | — | Real-time BUS Tracking SystemAI | 23/7/2025 | 17/6/2026 | Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative page of the affected product. | |
| Analizada | Baja (2) | 0.26% | — | Phpgurukul Time Table Generator System | 21/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PHPGurukul Time Table Generator System 1.0. Affected is an unknown function of the file /admin/profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.23% | — | Real-time SEO Project Real-time SEO | 21/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0. | |
| Aplazada | Baja (2.1) | 0.25% | — | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display SystemAI | 18/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System up to 8.2. This affects an unknown part of the file /admin/system/structure/getdirectorydata/web/baseinfo/companyManage. The manipulation of the argument Struccture_ID leads to sql… | |
| Analizada | Baja (3.5) | 0.33% | — | Bytecodealliance Wasmtime | 18/7/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest inducing a panic in the host (embedder). The specific bug is triggered by calling `path_open` after calling `fd_renumber` with… | |
| Aplazada | Crítica (9.3) | 2.6% | 💥 Exploit | Idera Up.time Monitoring StationAI | 16/7/2025 | 17/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code… | |
| Aplazada | Media (4.3) | 0.37% | — | Timelineofficial Time-lineAI | 15/7/2025 | 17/6/2026 | The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found in the TIME LINE website where uploaded files (instruction/message media) are not strictly validated for type and size. A user may upload renamed or oversized files that can disrupt performance or… | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |