Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1829 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 7.1% | 💥 PoC | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 5/2/2025 | 17/6/2026 | Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (6.6) | 0.19% | — | Acronis Cyber Protect Cloud AgentAI | 31/1/2025 | 17/6/2026 | Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. | |
| Aplazada | Media (6.3) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 31/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. | |
| Aplazada | Media (6.3) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 31/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. | |
| Aplazada | Media (6.3) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 31/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. | |
| Aplazada | Media (6.3) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 31/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378. | |
| Modificada | Alta (7.5) | 0.58% | — | Wpmessiah Safe AI Malware Protection FOR WP | 30/1/2025 | 17/6/2026 | The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db() function in all versions up to, and including, 1.0.17. This makes it possible for unauthenticated attackers to retrieve a complete dump of the site's database. | |
| Analizada | Alta (7.5) | 0.23% | — | IBM Storage Protect FOR Virtual EnvironmentsIBM Storage Protect | 27/1/2025 | 17/6/2026 | IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Aplazada | Alta (7.1) | 0.22% | — | Madeglobal Better Protected PagesAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in madeglobal Better Protected Pages better-protected-pages allows Stored XSS.This issue affects Better Protected Pages: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Marcucci Password Protect PluginAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored XSS.This issue affects Password Protect Plugin for WordPress: from n/a through <= 0.8.1.0. | |
| Analizada | Media (6.8) | 0.36% | — | I0bit Protected Folder | 5/1/2025 | 17/6/2026 | A vulnerability was found in IObit Protected Folder up to 13.6.0.5. It has been classified as problematic. Affected is the function 0x8001E000/0x8001E00C/0x8001E004/0x8001E010 in the library IURegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is… | |
| Analizada | Media (6.8) | 0.36% | — | I0bit Protected Folder | 5/1/2025 | 17/6/2026 | A vulnerability was found in IObit Protected Folder up to 13.6.0.5 and classified as problematic. This issue affects the function 0x8001E000/0x8001E004 in the library IUProcessFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The… | |
| Analizada | Media (6.8) | 0.36% | — | I0bit Protected Folder | 5/1/2025 | 17/6/2026 | A vulnerability has been found in IOBit Protected Folder up to 1.3.0 and classified as problematic. This vulnerability affects the function 0x22200c in the library pffilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has… | |
| Aplazada | Media (5.5) | 0.11% | — | Acronis Cyber ProtectAI | 2/1/2025 | 17/6/2026 | Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. | |
| Aplazada | Media (6.1) | 0.23% | — | Acronis Cyber Protect 16AI | 2/1/2025 | 17/6/2026 | Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. | |
| Analizada | Alta (7.8) | 0.17% | — | Acronis Cyber Protect | 2/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. | |
| Aplazada | Media (4.4) | 0.17% | — | Acronis Cyber Protect 16AIAcronis Cyber Protect Cloud AgentAI | 2/1/2025 | 17/6/2026 | Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895. | |
| Analizada | Media (6.1) | 0.29% | — | Acronis Cyber Protect | 2/1/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169. | |
| Analizada | Alta (7.8) | 0.17% | — | Acronis Cyber Protect | 2/1/2025 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. | |
| Aplazada | Baja (2.5) | 0.11% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber ProtectAI | 23/12/2024 | 17/6/2026 | Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 (Linux) before build 39938. | |
| Aplazada | Media (5.2) | 0.15% | — | Milestonesys XprotectAI | 19/12/2024 | 17/6/2026 | Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions. | |
| Aplazada | Alta (8.8) | 0.70% | — | Cleantalk Spam Protection Antispam FirewallAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10. | |
| Aplazada | Media (6.5) | 0.66% | — | Mindutopia Protected Posts Logout ButtonAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Nate Reist Protected Posts Logout Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protected Posts Logout Button: from n/a through 1.4.5. | |
| Aplazada | Media (5.3) | 0.57% | — | Fantasticplugins Fantastic Content Protector FreeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fantastic Content Protector Free: from n/a through 2.6. | |
| Aplazada | Media (6.1) | 0.29% | — | Wordpress Drag Drop Builder Human Face Detector PRE Built Templates Spam Protection User Email Notifications MoreAI | 7/12/2024 | 17/6/2026 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping.… |