Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.30%—Posimyth Innovation THE Plus Addons FOR Elementor PROAI1/7/202517/6/2026
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7.
AnalizadaMedia (5.5)1.1%—Dromara Ruoyi-vue-plus30/6/202517/6/2026
A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath leads to path…
AplazadaAlta (7.1)0.12%—Gopiplus Image Slider With DescriptionAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gopi_plus Image Slider With Description image-slider-with-description allows Stored XSS.This issue affects Image Slider With Description: from n/a through <= 9.2.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
AnalizadaAlta (8.1)1.3%—Zohocorp Manageengine Exchange Reporter Plus26/6/202517/6/2026
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
AnalizadaBaja (2.1)0.47%—Xxyopen Novel-plus24/6/202517/6/2026
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml of the component User Management Module. The manipulation of the argument sort/order leads to sql…
AnalizadaBaja (1.3)0.48%—Xxyopen Novel-plus24/6/202517/6/2026
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Handler. The manipulation leads to improper control of resource…
AnalizadaBaja (2.9)0.56%—Xxyopen Novel-plus24/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to…
AnalizadaCrítica (9.8)1.6%—Xxyopen Novel-plus20/6/202517/6/2026
Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter
AplazadaMedia (5.4)0.32%—Climaxthemes Kata PlusAI20/6/202517/6/2026
Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3.
AplazadaMedia (4.3)0.14%—Cyberchimps Responsive PlusAI17/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Request Forgery.This issue affects Responsive Plus: from n/a through <= 3.2.2.
AplazadaAlta (8.8)2.6%—Dell Controlvault3AIDell Controlvault3 PlusAI13/6/202517/6/2026
An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability.
AplazadaAlta (8.1)2.6%—Dell Controlvault3AIDell Controlvault3 PlusAI13/6/202517/6/2026
A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault…
AplazadaAlta (8.8)2.1%—Dell Controlvault3AIDell Controlvault 3 PlusAI13/6/202517/6/2026
An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this…
AplazadaAlta (8.8)3.4%—Dell Controlvault3AIDell Controlvault3 PlusAI13/6/202517/6/2026
A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this…
AplazadaAlta (8.4)1.9%—Dell Controlvault3AIDell Controlvault3 PlusAI13/6/202517/6/2026
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability.
ModificadaCrítica (9.8)0.57%—G5plus Essential Real Estate9/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.9.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
AnalizadaCrítica (9.6)2.2%—Zohocorp Manageengine Exchange Reporter Plus9/6/202517/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
AnalizadaAlta (8.3)1.6%—Zohocorp Manageengine Adaudit Plus9/6/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
AplazadaMedia (5.4)0.32%—Buddydev Activity Plus ReloadedAIBuddypressAI6/6/202517/6/2026
Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
AplazadaMedia (6.5)0.20%—Posimyth THE Plus Addons FOR Elementor Page BuilderAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.2.7.
AplazadaMedia (5.4)0.25%—Cyberchimps Responsive PlusAI6/6/202517/6/2026
Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through <= 3.2.0.
AnalizadaAlta (8.7)0.74%—Totolink N302r Plus Firmware5/6/202517/6/2026
A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be…
Orbitaley — Vulnerabilidades