Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | Simple Football ScoreboardAI | 21/3/2026 | 17/6/2026 | The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.36% | — | Scoreboard FOR Html5 Games LiteAI | 21/3/2026 | 17/6/2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small… | |
| Analizada | Alta (7.2) | 0.86% | — | Dreamfactory Core | 20/3/2026 | 17/6/2026 | An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. | |
| Modificada | Alta (8.8) | 0.38% | — | Aster-te Terrapack TkservercgiAster-te Terrapack TkwebcorengAster-te Terrapack Tpkwebgis | 20/3/2026 | 5/7/2026 | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0. | |
| Analizada | Alta (7.5) | 0.28% | — | Bitcoin Core | 20/3/2026 | 17/6/2026 | Bitcoin Core 0.13.0 through 29.x has an integer overflow. | |
| Analizada | Media (5.3) | 0.33% | — | Bitcoin Core | 20/3/2026 | 17/6/2026 | Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. | |
| Analizada | Media (5.8) | 0.42% | — | Amazon Bedrock Agentcore Starter Toolkit | 16/3/2026 | 17/6/2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who… | |
| Aplazada | Baja (2.1) | 0.35% | — | Flowci Flow-core-xAI | 16/3/2026 | 17/6/2026 | A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java of the component SMTP Host Handler. The manipulation results in server-side request forgery. The attack may be… | |
| Aplazada | Media (6.5) | 0.22% | — | Themefusion Avada CoreAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Themefusion Avada CoreAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeFusion Avada Core fusion-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avada Core: from n/a through < 5.15.0. | |
| Aplazada | Alta (7.5) | 0.51% | — | Themelexus Medilazar-coreAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7. | |
| Aplazada | Alta (7.5) | 0.51% | — | Radiustheme Medilink-coreAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7. | |
| Analizada | Alta (7.5) | 0.32% | — | Ellanetworks Ella Core | 13/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algorithm bitstrings, resulting in a denial of service. An attacker able to send crafted NGAP messages to… | |
| Analizada | Alta (7.5) | 0.54% | — | Ellanetworks Ella Core | 13/3/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected… | |
| Modificada | Alta (7.5) | 2.5% | — | Microsoft Asp.net Core | 10/3/2026 | 15/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 0.79% | — | Coredns.io Coredns | 6/3/2026 | 15/7/2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number… | |
| Modificada | Media (6.3) | 0.48% | — | Coredns.io Coredns | 6/3/2026 | 15/7/2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw.… | |
| Modificada | Alta (8.7) | 0.79% | — | Fasterxml Jackson-core | 6/3/2026 | 15/7/2026 | jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constraint (default: 500)… | |
| Aplazada | Alta (7.1) | 0.26% | — | Pixfort CoreAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixFort pixfort Core pixfort-core allows Reflected XSS.This issue affects pixfort Core: from n/a through <= 3.2.22. | |
| Aplazada | Media (6.3) | 0.27% | — | Pixfort CoreAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22. | |
| Aplazada | Media (5.9) | 0.33% | 💥 PoC | Inseriswiss Inseri CoreAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5. | |
| Aplazada | Alta (8.1) | 0.58% | — | Mikado-themes Topscore - Sports Wordpress ThemeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Don-themes Riode CoreAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind SQL Injection.This issue affects Riode Core: from n/a through <= 1.6.26. | |
| Analizada | Alta (8.2) | 1.0% | — | Underscorejs Underscore | 3/3/2026 | 17/6/2026 | Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be… | |
| Modificada | Baja (2) | 0.60% | — | Erlang Rebar3HEXHEX Core | 27/2/2026 | 17/6/2026 | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl,… |