Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | Posimyth Innovation THE Plus Addons FOR Elementor PROAI | 1/7/2025 | 17/6/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7. | |
| Analizada | Media (5.5) | 1.1% | — | Dromara Ruoyi-vue-plus | 30/6/2025 | 17/6/2026 | A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath leads to path… | |
| Aplazada | Alta (7.1) | 0.12% | — | Gopiplus Image Slider With DescriptionAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gopi_plus Image Slider With Description image-slider-with-description allows Stored XSS.This issue affects Image Slider With Description: from n/a through <= 9.2. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. | |
| Analizada | Baja (2.1) | 0.47% | — | Xxyopen Novel-plus | 24/6/2025 | 17/6/2026 | A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml of the component User Management Module. The manipulation of the argument sort/order leads to sql… | |
| Analizada | Baja (1.3) | 0.48% | — | Xxyopen Novel-plus | 24/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Handler. The manipulation leads to improper control of resource… | |
| Analizada | Baja (2.9) | 0.56% | — | Xxyopen Novel-plus | 24/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to… | |
| Analizada | Crítica (9.8) | 1.6% | — | Xxyopen Novel-plus | 20/6/2025 | 17/6/2026 | Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter | |
| Aplazada | Media (5.4) | 0.32% | — | Climaxthemes Kata PlusAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Cyberchimps Responsive PlusAI | 17/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Request Forgery.This issue affects Responsive Plus: from n/a through <= 3.2.2. | |
| Aplazada | Alta (8.8) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. | |
| Aplazada | Alta (8.1) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault… | |
| Aplazada | Alta (8.8) | 2.1% | — | Dell Controlvault3AIDell Controlvault 3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.8) | 3.4% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.4) | 1.9% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.57% | — | G5plus Essential Real Estate | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.9. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. | |
| Analizada | Crítica (9.6) | 2.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. | |
| Aplazada | Media (5.4) | 0.32% | — | Buddydev Activity Plus ReloadedAIBuddypressAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Posimyth THE Plus Addons FOR Elementor Page BuilderAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.2.7. | |
| Aplazada | Media (5.4) | 0.25% | — | Cyberchimps Responsive PlusAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through <= 3.2.0. | |
| Analizada | Alta (8.7) | 0.74% | — | Totolink N302r Plus Firmware | 5/6/2025 | 17/6/2026 | A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be… |