Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.65%—RadashiAI27/5/202517/6/2026
Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to…
AplazadaCrítica (9.3)0.43%—Kamleshyadav Pixel Wordpress Form Builder Plugin & AutoresponderAI23/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Blind SQL Injection.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.2.
AnalizadaAlta (8.3)1.5%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
AnalizadaAlta (8.3)37%—Zohocorp Manageengine Adaudit Plus23/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
AnalizadaAlta (8.3)1.7%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
AnalizadaAlta (8.3)5.9%—Zohocorp Manageengine Adaudit Plus22/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
AplazadaCrítica (9.8)10%💥 ExploitMadaraAI21/5/202517/6/2026
The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…
AnalizadaMedia (6.5)0.19%—IBM Security Qradar EDR20/5/202517/6/2026
IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.
AnalizadaMedia (6.5)0.24%—IBM Security Qradar EDR20/5/202517/6/2026
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.
ModificadaMedia (5.4)0.21%—Aptivada FOR WP16/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP aptivada-for-wp allows DOM-Based XSS.This issue affects Aptivada for WP: from n/a through <= 2.0.0.
AplazadaMedia (5.4)0.15%—Kamleshyadav Pixel Wordpress Form Builder Plugin AND AutoresponderAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Site Request Forgery.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.3.
AnalizadaAlta (8.1)1.7%—Zohocorp Manageengine Adaudit Plus14/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
AplazadaMedia (5.4)0.13%—Intel Ethernet Network Adapter E810 NVM Update UtilityAI13/5/202517/6/2026
Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.15%—Intel Network Adapter DriverAI13/5/202517/6/2026
Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.14%—Intel Network Adapters Administrative ToolsAI13/5/202517/6/2026
Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (8.6)0.56%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense7/5/202511/8/2026
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…
AplazadaMedia (6.5)0.27%—Padam Shankhadev Nepali-post-dateAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Nepali Post Date nepali-post-date allows Stored XSS.This issue affects Nepali Post Date: from n/a through <= 5.1.1.
AnalizadaMedia (5.1)6.2%—Westboy Cicadascms19/4/202517/6/2026
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaAlta (8.8)0.61%—Open-metadata Openmetadata17/4/202517/6/2026
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.
AnalizadaMedia (5.3)0.57%—Westboy Cicadascms14/4/202517/6/2026
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.5)0.40%—IBM Qradar Wincollect11/4/202517/6/2026
IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources.
AplazadaCrítica (9.8)0.39%💥 PoCAdam Nowak Buddypress HumanityAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.
AplazadaAlta (7.1)0.21%—Renzo Tejada Libro DE Reclamaciones Y QuejasAI4/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Renzo Tejada Libro de Reclamaciones y Quejas libro-de-reclamaciones-y-quejas allows Cross Site Request Forgery.This issue affects Libro de Reclamaciones y Quejas: from n/a through <= 1.0.
AplazadaMedia (5.4)0.45%—Shortpixel Adaptive ImagesAI1/4/202517/6/2026
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.10.0.
AplazadaCrítica (9.9)0.77%—Adamskaat Countdown & ClockAI1/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock countdown-builder allows Remote Code Inclusion.This issue affects Countdown & Clock: from n/a through <= 2.8.8.