Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.74% | — | Totolink N302r Plus Firmware | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the… | |
| Analizada | Alta (8.2) | 0.30% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+221 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while processing goodbye RTCP packet from network. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+230 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. | |
| Analizada | Alta (8.2) | 0.24% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+77 | 3/6/2025 | 17/6/2026 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+189 | 3/6/2025 | 17/6/2026 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. | |
| Analizada | Media (4.1) | 0.32% | — | Updraftplus Wp-optimize | 2/6/2025 | 17/6/2026 | The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations. | |
| Modificada | Media (4.3) | 0.29% | — | Krasenslavov Featured Image Plus | 30/5/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.3) | 1.5% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. | |
| Analizada | Alta (8.3) | 37% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. | |
| Analizada | Media (5.5) | 0.22% | — | Sandboxie-plus Sandboxie | 22/5/2025 | 17/6/2026 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_SetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the pointer the user has passed in is safe to read from. SetRegValue then… | |
| Analizada | Alta (7.8) | 0.23% | — | Sandboxie-plus Sandboxie | 22/5/2025 | 17/6/2026 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_GetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the pointer the user has passed in is safe to write to. GetRegValue then… | |
| Analizada | Alta (7.8) | 0.24% | — | Sandboxie-plus Sandboxie | 22/5/2025 | 17/6/2026 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a extremely large copy into the small allocation. Version 1.15.12 fixes… | |
| Analizada | Alta (7.8) | 0.23% | — | Sandboxie-plus Sandboxie | 22/5/2025 | 17/6/2026 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have an arithmetic overflow deep in the memory allocation subsystem that would lead to a smaller allocation than requested, and a buffer… | |
| Analizada | Alta (8.3) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. | |
| Analizada | Alta (8.3) | 5.9% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. | |
| Analizada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Elbisnero WpeventplusAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Modificada | Media (5.4) | 1.3% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 5/7/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and… | |
| Analizada | Alta (8.8) | 12% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN… | |
| Analizada | Media (5.4) | 8.5% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | |
| Analizada | Alta (8.1) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. | |
| Analizada | Alta (8.1) | 45% | — | Zohocorp Manageengine Adselfservice Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | |
| Analizada | Media (5.1) | 0.21% | 💥 PoC | Cpplusworld Cp-xr-de21-s Firmware | 13/5/2025 | 17/6/2026 | CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any… | |
| Aplazada | Media (5.3) | 0.33% | — | Cyberchimps Responsive PlusAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Plus: from n/a through <= 3.1.9. |