Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
401.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.19% | — | — | 2/10/2026 | 2/10/2026 | An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted… | |
| Pendiente de análisis | Crítica (9.4) | 0.34% | — | — | 2/10/2026 | 2/10/2026 | A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.3) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (4.8) | 0.23% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”. | |
| Aplazada | Media (4.8) | 0.29% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”. | |
| Aplazada | Media (4.8) | 0.29% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”. | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Online Admission SystemAI | 2/10/2026 | 2/10/2026 | A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (6.1) | 0.26% | — | Wp-statistics WP StatisticsAI | 2/10/2026 | 3/10/2026 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.23% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Amauri Wpmobile.appAI | 2/10/2026 | 2/10/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate… | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (4.3) | 0.28% | — | Monetizemore Advanced ADSAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26. | |
| Aplazada | Alta (7.2) | 0.24% | — | Boldgrid W3 Total CacheAI | 2/10/2026 | 3/10/2026 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.21% | — | Aioseo ALL IN ONE SEOAI | 2/10/2026 | 3/10/2026 | The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (8.8) | 0.29% | — | Havelsan SEFAI | 2/10/2026 | 2/10/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (4.8) | 0.38% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is affected – endpoint “/es/clientypes/update/109441”. | |
| Aplazada | Media (4.8) | 0.38% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomGrupoEmpresarial” parameter is affected – endpoint "/es/corporategroups/update/246”. | |
| Aplazada | Media (4.8) | 0.23% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affected – endpoint “/es/lostmotives/store”. | |
| Aplazada | Media (4.8) | 0.23% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”. | |
| Aplazada | Media (4.8) | 0.23% | — | RepasatAI | 2/10/2026 | 2/10/2026 | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomDelegacion” parameter is affected – endpoint “/es/delegations/store”. |