Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cross Site Request Forgery.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6. | |
| Aplazada | Crítica (9.8) | 7.9% | 💥 Exploit | Alfresco Community EditionAI | 17/6/2025 | 17/6/2026 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch. | |
| Aplazada | Media (6.8) | 0.40% | — | Portainer Community EditionAI | 17/6/2025 | 17/6/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,… | |
| Aplazada | Alta (8.4) | 0.23% | — | Fujielectric Smart EditorAI | 17/6/2025 | 17/6/2026 | Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. | |
| Aplazada | Alta (8.4) | 0.22% | — | Fujielectric Smart EditorAI | 17/6/2025 | 17/6/2026 | Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | |
| Aplazada | Alta (8.4) | 0.19% | — | Fujielectric Smart EditorAI | 17/6/2025 | 17/6/2026 | Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code. | |
| Aplazada | Media (5.3) | 0.33% | — | Roland Beaussant Audio Editor RecorderAI | 10/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audio Editor & Recorder: from n/a through <= 2.2.1. | |
| Aplazada | Alta (7.2) | 0.35% | — | LTL Freight Quotes Freightview EditionAILTL Freight Quotes Daylight EditionAILTL Freight Quotes DAY Ross EditionAI | 7/6/2025 | 17/6/2026 | The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respectively, due to… | |
| Aplazada | Alta (7.4) | 0.19% | — | PoeditorAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= 0.9.10. | |
| Aplazada | Media (4.3) | 0.16% | — | Michael Cannon Custom Bulkquick EditAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cross Site Request Forgery.This issue affects Custom Bulk/Quick Edit: from n/a through <= 1.6.10. | |
| Aplazada | Media (4.8) | 0.18% | — | PoeditAI | 22/5/2025 | 17/6/2026 | MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously… | |
| Aplazada | Media (5.4) | 0.26% | — | Enituretechnology LTL Freight Quotes Freightquote EditionAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through <= 2.3.11. | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul Credit Card Application Management System | 19/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.48% | — | Phpgurukul Credit Card Application Management System | 19/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.5) | 0.30% | — | Flickdevs Countdown Timer FOR Wordpress Block Editor | 15/5/2025 | 17/6/2026 | The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Baja (2) | 0.35% | — | Paloaltonetworks Prisma Cloud Compute EditionAI | 14/5/2025 | 17/6/2026 | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue. | |
| Aplazada | Alta (8.3) | 0.47% | — | SAP S/4hana Cloud Private EditionAISAP S/4hana ON PremiseAI | 13/5/2025 | 17/6/2026 | SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs. This is due to lack of input validation and no authorization… | |
| Aplazada | Media (5.9) | 0.27% | — | Aharonyan WP Front User SubmitAIAleksanaharonyan Front EditorAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Stored XSS.This issue affects WP Front User Submit / Front Editor: from n/a through <= 5.0.6. | |
| Aplazada | Media (5.4) | 0.16% | — | Pimwick PW Woocommerce Bulk EditAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit pw-bulk-edit allows Cross Site Request Forgery.This issue affects PW WooCommerce Bulk Edit: from n/a through <= 2.134. | |
| Aplazada | Media (6.5) | 0.39% | — | Elex Woocommerce Advanced Bulk Edit Products Prices AttributesAI | 24/4/2025 | 17/6/2026 | The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Alta (7.3) | 0.39% | — | Ueditor Project Ueditor | 23/4/2025 | 1/10/2026 | Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. | |
| Aplazada | Crítica (9.8) | 0.42% | — | MUM MapeditAI | 22/4/2025 | 17/6/2026 | MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpfactory Product Excel Import Export Bulk Edit FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from… | |
| Aplazada | Media (6.5) | 0.38% | — | Fadi MED Editor Wysiwyg Background ColorAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color editor-wysiwyg-background-color allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editor Wysiwyg Background Color: from n/a through <= 1.0. | |
| Analizada | Media (4.9) | 0.53% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information. |