Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Victortihai Morningtime LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai MorningTime Lite morningtime-lite allows Stored XSS.This issue affects MorningTime Lite: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.45% | — | Arraytics TimeticsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.29. | |
| Analizada | Media (5.3) | 0.59% | — | Projectworlds Online Time Table Generator | 23/3/2025 | 17/6/2026 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.69% | — | Projectworlds Online Time Table Generator | 23/3/2025 | 17/6/2026 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /staff/index.php. The manipulation of the argument e leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.53% | — | Projectworlds Online Time Table Generator | 23/3/2025 | 17/6/2026 | A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.53% | — | Projectworlds Online Time Table Generator | 23/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6) | 0.39% | — | Uptime KumaAI | 17/3/2025 | 17/6/2026 | Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack. | |
| Analizada | Alta (7.8) | 0.19% | — | Jetbrains Runtime | 12/3/2025 | 17/6/2026 | In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible | |
| Analizada | Media (4.8) | 0.25% | — | Gkdv Blogbuzztime FOR WP | 12/3/2025 | 17/6/2026 | The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (5.9) | 0.29% | — | Popeating Post Read TimeAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in popeating Post Read Time post-read-time allows Stored XSS.This issue affects Post Read Time: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.2) | 0.56% | — | BabelAIBabel HelpersAIBabel RuntimeAIBabel CoreAI | 11/3/2025 | 17/6/2026 | Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e.… | |
| Analizada | Alta (7.1) | 0.33% | — | Yaidier Countdown Timer | 11/3/2025 | 17/6/2026 | The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Baja (3.1) | 0.22% | — | SAP Just IN TimeAI | 11/3/2025 | 17/6/2026 | SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted. | |
| Aplazada | Alta (7.1) | 0.39% | — | Dreamstime Stock PhotosAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dreamstime Dreamstime Stock Photos dreamstime-stock-photos allows Reflected XSS.This issue affects Dreamstime Stock Photos: from n/a through <= 4.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Antrouss UnitimetableAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antrouss UniTimetable unitimetable allows Stored XSS.This issue affects UniTimetable: from n/a through <= 1.1. | |
| Analizada | Alta (7.1) | 0.35% | — | Agilelogix Post Timeline | 26/2/2025 | 17/6/2026 | The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (5.9) | 0.34% | — | Flickdevs Countdown Timer FOR Elementor | 26/2/2025 | 17/6/2026 | The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks. | |
| Analizada | Alta (7.1) | 0.63% | 💥 Exploit | Elementengage Simple Certain Time TO Show Content | 26/2/2025 | 17/6/2026 | The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.5) | 0.28% | — | Bplugins Countdown TimerAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer countdown-time allows Stored XSS.This issue affects Countdown Timer: from n/a through <= 1.2.6. | |
| Aplazada | Media (4.3) | 0.22% | — | O-ran Near Realtime RICAI | 25/2/2025 | 17/6/2026 | An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection between a gNB and the Near RT-RIC by inundating the system with a high volume of subscription requests via an xApp. | |
| Aplazada | Media (5.7) | 0.24% | — | O-ran Near Realtime RICAI | 25/2/2025 | 17/6/2026 | An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a significant quantity of E2 Subscription Requests originating from an xApp. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (5.4) | 0.24% | — | Novachron Zeitsysteme Gmbh & CO. KG Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (6.5) | 0.24% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request. | |
| Aplazada | Media (6.5) | 0.23% | — | Bplugins Timeline BlockAI | 17/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Timeline Block timeline-block-block allows Stored XSS.This issue affects Timeline Block: from n/a through <= 1.1.1. |