Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | HurrytimerAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Nabil Lemsieh HurryTimer hurrytimer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HurryTimer: from n/a through <= 2.13.1. | |
| Analizada | Media (5.4) | 0.19% | — | Bernhard-riedl Timezonecalculator | 26/6/2025 | 17/6/2026 | The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalculator_output' shortcode in all versions up to, and including, 3.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.40% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.4. | |
| Modificada | Crítica (9.9) | 0.86% | 💥 PoC | Efrotech Timetrax | 18/6/2025 | 5/7/2026 | An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form | |
| Aplazada | Alta (7.1) | 0.28% | — | Revmakx Backup AND Staging BY WP Time CapsuleAIRevmakx WP Time CapsuleAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Pressgrid - Frontend Publish Reaction & Multimedia ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Codepeople WP Time Slots Booking FormAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Cross Site Request Forgery.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.30. | |
| Aplazada | Media (5.9) | 0.25% | — | Powiet Powies Uptime RobotAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PowieT Powie's Uptime Robot powies-uptime-robot allows Stored XSS.This issue affects Powie's Uptime Robot: from n/a through <= 0.9.7. | |
| Aplazada | Alta (7.1) | 0.22% | — | Daman Jeet Real Time Validation FOR Gravity FormsAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows Reflected XSS.This issue affects Real Time Validation for Gravity Forms: from n/a through <= 1.7.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Daman Jeet Real-time-validation-for-gravity-formsAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows Cross Site Request Forgery.This issue affects Real Time Validation for Gravity Forms: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7) | 0.16% | — | PC Time TracerAI | 3/6/2025 | 17/6/2026 | Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker. | |
| Aplazada | Media (6.9) | 0.65% | — | TimeworksAI | 3/6/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker. | |
| Analizada | Media (6.9) | 0.39% | — | Zkteco Biotime | 27/5/2025 | 17/6/2026 | ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password"). | |
| Aplazada | Crítica (9.3) | 0.49% | — | Mobatime AMX MtapiAI | 27/5/2025 | 17/6/2026 | Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5. | |
| Aplazada | Crítica (9.3) | 0.42% | — | AES Multimedia GestnetAI | 26/5/2025 | 17/6/2026 | SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘fk_remoto_central’ parameter on the ‘/webservices/articles.php’ endpoint. | |
| Analizada | Media (4.8) | 0.25% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0. | |
| Analizada | Media (4.8) | 0.31% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0. | |
| Analizada | Media (4.8) | 0.25% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0. | |
| Analizada | Media (6.9) | 0.51% | — | Projectworlds Online Time Table Generator | 20/5/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_teacher.php. The manipulation of the argument e leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.51% | — | Projectworlds Online Time Table Generator | 20/5/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. The manipulation of the argument c/subname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.51% | — | Projectworlds Online Time Table Generator | 20/5/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.22% | — | Fyrewurks Tiki TimeAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time allows Reflected XSS.This issue affects Tiki Time: from n/a through 1.3. | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Multimedia Responsive Carousel With Image Video Audio SupportAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Video Audio Support multimedia-carousel allows SQL Injection.This issue affects Multimedia Responsive Carousel with Image Video Audio Support: from n/a through <=… | |
| Analizada | Media (6.5) | 0.30% | — | Flickdevs Countdown Timer FOR Wordpress Block Editor | 15/5/2025 | 17/6/2026 | The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Alta (7) | 0.28% | — | Bytecodealliance Webassembly Micro Runtime | 15/5/2025 | 17/6/2026 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following… |