Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.32% | — | Mrcen Springboot-ucan-adminAI | 8/4/2025 | 17/6/2026 | A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index of the component Personal Settings Interface. The manipulation leads to cross site scripting. It is possible to… | |
| Analizada | Media (5.3) | 0.33% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.40% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.54% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.55% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argument description leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.1) | 0.38% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.1) | 0.38% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resource/add. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (4.3) | 0.15% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request Forgery.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Aplazada | Media (4.3) | 0.16% | — | WP Spotlight Advanced ALL IN ONE Admin SearchAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight wp-spotlight-search allows Cross Site Request Forgery.This issue affects Advanced All in One Admin Search by WP Spotlight: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.40% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quý Lê 91 Administrator Z administrator-z allows DOM-Based XSS.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Analizada | Media (5.1) | 0.41% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation of the argument motto leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.49% | — | Eladmin | 4/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The attack may be launched remotely. The… | |
| Aplazada | Media (5.1) | 0.22% | — | M-files Server Admin ToolAI | 4/4/2025 | 17/6/2026 | Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI | |
| Analizada | Media (6.1) | 0.32% | — | Pgadmin 4 | 3/4/2025 | 17/6/2026 | pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser. | |
| Analizada | Alta (8.8) | 56% | 💥 Exploit | Pgadmin 4 | 3/4/2025 | 17/6/2026 | Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the… | |
| Analizada | Media (6.6) | 0.48% | — | Admin LTE Theme Project Admin LTE Theme | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*. | |
| Analizada | Media (6.6) | 0.48% | — | Material Admin Project Material Admin | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*. | |
| Aplazada | Alta (7.1) | 0.13% | — | Admingeekz Varnish-wpAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress varnish-wp allows Cross Site Request Forgery.This issue affects Varnish WordPress: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.36% | — | Administrator ZAI | 28/3/2025 | 17/6/2026 | The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminz_import_backup() function in all versions up to, and including, 2025.03.24. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.1) | 0.54% | — | Eladmin | 27/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched remotely. | |
| Aplazada | Crítica (9.3) | 0.61% | — | Andy Moyle Church-adminAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin allows SQL Injection.This issue affects Church Admin: from n/a through <= 5.0.18. | |
| Aplazada | Alta (7.1) | 0.19% | — | Donald Gilbert Wordpress Admin BAR ImprovedAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved wordpress-admin-bar-improved allows Stored XSS.This issue affects WordPress Admin Bar Improved: from n/a through <= 3.3.5. | |
| Aplazada | Media (6.1) | 0.34% | — | Easy Custom Admin BARAI | 22/3/2025 | 17/6/2026 | The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.9) | 0.36% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’, ‘searchSpecialitiesPending’, ‘searchSpecialitiesLinked’,… |