Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.15%—Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cross Site Request Forgery.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6.
AplazadaCrítica (9.8)7.9%💥 ExploitAlfresco Community EditionAI17/6/202517/6/2026
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.
AplazadaMedia (6.8)0.40%—Portainer Community EditionAI17/6/202517/6/2026
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,…
AplazadaAlta (8.4)0.23%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
AplazadaAlta (8.4)0.22%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
AplazadaAlta (8.4)0.19%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
AplazadaMedia (5.3)0.33%—Roland Beaussant Audio Editor RecorderAI10/6/202517/6/2026
Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audio Editor & Recorder: from n/a through <= 2.2.1.
AplazadaAlta (7.2)0.35%—LTL Freight Quotes Freightview EditionAILTL Freight Quotes Daylight EditionAILTL Freight Quotes DAY Ross EditionAI7/6/202517/6/2026
The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respectively, due to…
AplazadaAlta (7.4)0.19%—PoeditorAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= 0.9.10.
AplazadaMedia (4.3)0.16%—Michael Cannon Custom Bulkquick EditAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cross Site Request Forgery.This issue affects Custom Bulk/Quick Edit: from n/a through <= 1.6.10.
AplazadaMedia (4.8)0.18%—PoeditAI22/5/202517/6/2026
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously…
AplazadaMedia (5.4)0.26%—Enituretechnology LTL Freight Quotes Freightquote EditionAI19/5/202517/6/2026
Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through <= 2.3.11.
AnalizadaMedia (6.9)0.58%—Phpgurukul Credit Card Application Management System19/5/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.48%—Phpgurukul Credit Card Application Management System19/5/202517/6/2026
A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.5)0.30%—Flickdevs Countdown Timer FOR Wordpress Block Editor15/5/202517/6/2026
The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaBaja (2)0.35%—Paloaltonetworks Prisma Cloud Compute EditionAI14/5/202517/6/2026
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
AplazadaAlta (8.3)0.47%—SAP S/4hana Cloud Private EditionAISAP S/4hana ON PremiseAI13/5/202517/6/2026
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs. This is due to lack of input validation and no authorization…
AplazadaMedia (5.9)0.27%—Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Stored XSS.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6.
AplazadaMedia (5.4)0.16%—Pimwick PW Woocommerce Bulk EditAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit pw-bulk-edit allows Cross Site Request Forgery.This issue affects PW WooCommerce Bulk Edit: from n/a through <= 2.134.
AplazadaMedia (6.5)0.39%—Elex Woocommerce Advanced Bulk Edit Products Prices AttributesAI24/4/202517/6/2026
The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaAlta (7.3)0.39%—Ueditor Project Ueditor23/4/20251/10/2026
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
AplazadaCrítica (9.8)0.42%—MUM MapeditAI22/4/202517/6/2026
MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.
AplazadaAlta (7.1)0.29%—Wpfactory Product Excel Import Export Bulk Edit FOR WoocommerceAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from…
AplazadaMedia (6.5)0.38%—Fadi MED Editor Wysiwyg Background ColorAI17/4/202517/6/2026
Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color editor-wysiwyg-background-color allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editor Wysiwyg Background Color: from n/a through <= 1.0.
AnalizadaMedia (4.9)0.53%—Benjaminrojas WP Editor17/4/202517/6/2026
The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information.