Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.15%—Aftabhusain Hide Admin BAR From Front ENDAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Husain Hide Admin Bar From Front End hide-admin-bar-from-front-end allows Cross Site Request Forgery.This issue affects Hide Admin Bar From Front End: from n/a through <= 1.0.0.
AnalizadaMedia (6.5)0.31%—Admin Audit Trail Project Admin Audit Trail11/6/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.
AplazadaMedia (4.3)0.15%—Minhlaobao Admin NotesAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.This issue affects Admin Notes: from n/a through <= 1.1.
AplazadaAlta (8.9)0.73%—Mimsoftware MIM Admin ServiceAI4/6/202517/6/2026
CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted request over the RMI interface to execute arbitrary code with the privileges of the MIM Admin service. The RMI interface is only accessible locally (listening on…
AplazadaAlta (7)0.36%—Tibco Activematrix AdministratorAI21/5/202517/6/2026
Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.
AplazadaAlta (7.1)0.13%—Shayan Farhang Pazhooh Shayanweb Admin FontchangerAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fontchanger allows Stored XSS.This issue affects ShayanWeb Admin FontChanger: from n/a through <= 1.9.1.
AplazadaMedia (5.4)0.14%—Intel Network Adapters Administrative ToolsAI13/5/202517/6/2026
Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)0.41%—Owladmin OWL Admin13/5/202517/6/2026
owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.
AnalizadaMedia (5.3)0.57%—Continew Admin12/5/202517/6/2026
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (5.1)0.40%—Continew Admin11/5/202517/6/2026
A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The manipulation of the argument File leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.1)0.38%—Jadmin-java Jadmin10/5/202517/6/2026
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.78%—Jadmin-java Jadmin9/5/202517/6/2026
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.39%—Wpase Admin AND Site Enhancements28/4/202517/6/2026
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request
AnalizadaMedia (5.3)0.52%—Opplus Springboot-admin27/4/202517/6/2026
A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao.xml. The manipulation of the argument order leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AplazadaMedia (6.1)0.33%—Custom Admin BAR FavoritesAI25/4/202517/6/2026
The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (7.1)0.29%—Rtowebsites AdminquickbarAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites AdminQuickbar adminquickbar allows Reflected XSS.This issue affects AdminQuickbar: from n/a through <= 1.9.1.
AplazadaMedia (4.9)0.69%—QUY LE 91 Administrator ZAI16/4/202517/6/2026
Path Traversal: '.../...//' vulnerability in Quý Lê 91 Administrator Z administrator-z allows Path Traversal.This issue affects Administrator Z: from n/a through <= 2025.03.28.
AplazadaMedia (6.5)0.35%—Andy Moyle Church AdminAI16/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin allows Stored XSS.This issue affects Church Admin: from n/a through <= 5.0.23.
AplazadaAlta (7.5)0.47%—Notfound Macro Calculator With Admin Email Optin AND DataAI15/4/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calculator with Admin Email Optin & Data: from n/a through 1.0.
AplazadaAlta (8.8)0.37%—QUY LE 91 Administrator ZAI15/4/202517/6/2026
Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a through <= 2025.03.24.
AplazadaAlta (8.8)0.40%—Wpclever WPC Admin ColumnsAI12/4/202517/6/2026
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated through the ajax_edit_save() function. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaMedia (5.9)0.40%—Eliot Akira Admin Menu Post ListAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliot Akira Admin Menu Post List admin-menu-post-list allows Stored XSS.This issue affects Admin Menu Post List: from n/a through <= 2.0.7.
AnalizadaMedia (6.2)1.1%—Microsoft Windows Admin Center8/4/202517/6/2026
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
AnalizadaBaja (1.8)0.25%—Pimcore Admin Classic Bundle8/4/202517/6/2026
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session cookie theft and the alteration of page content. The vulnerability…
AnalizadaMedia (5.3)0.54%—Opplus Springboot-admin8/4/202517/6/2026
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization. The attack can be launched…
Orbitaley — Vulnerabilidades