Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2676 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.24%—Simple Football ScoreboardAI21/3/202617/6/2026
The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.36%—Scoreboard FOR Html5 Games LiteAI21/3/202617/6/2026
The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small…
AnalizadaAlta (7.2)0.86%—Dreamfactory Core20/3/202617/6/2026
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.
ModificadaAlta (8.8)0.38%—Aster-te Terrapack TkservercgiAster-te Terrapack TkwebcorengAster-te Terrapack Tpkwebgis20/3/20265/7/2026
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0.
AnalizadaAlta (7.5)0.28%—Bitcoin Core20/3/202617/6/2026
Bitcoin Core 0.13.0 through 29.x has an integer overflow.
AnalizadaMedia (5.3)0.33%—Bitcoin Core20/3/202617/6/2026
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
AnalizadaMedia (5.8)0.42%—Amazon Bedrock Agentcore Starter Toolkit16/3/202617/6/2026
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who…
AplazadaBaja (2.1)0.35%—Flowci Flow-core-xAI16/3/202617/6/2026
A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java of the component SMTP Host Handler. The manipulation results in server-side request forgery. The attack may be…
AplazadaMedia (6.5)0.22%—Themefusion Avada CoreAI13/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0.
AplazadaMedia (5.3)0.29%—Themefusion Avada CoreAI13/3/202617/6/2026
Missing Authorization vulnerability in ThemeFusion Avada Core fusion-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avada Core: from n/a through < 5.15.0.
AplazadaAlta (7.5)0.51%—Themelexus Medilazar-coreAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7.
AplazadaAlta (7.5)0.51%—Radiustheme Medilink-coreAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.
AnalizadaAlta (7.5)0.32%—Ellanetworks Ella Core13/3/202617/6/2026
Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algorithm bitstrings, resulting in a denial of service. An attacker able to send crafted NGAP messages to…
AnalizadaAlta (7.5)0.54%—Ellanetworks Ella Core13/3/202617/6/2026
Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected…
ModificadaAlta (7.5)2.5%—Microsoft Asp.net Core10/3/202615/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)0.79%—Coredns.io Coredns6/3/202615/7/2026
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number…
ModificadaMedia (6.3)0.48%—Coredns.io Coredns6/3/202615/7/2026
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw.…
ModificadaAlta (8.7)0.79%—Fasterxml Jackson-core6/3/202615/7/2026
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constraint (default: 500)…
AplazadaAlta (7.1)0.26%—Pixfort CoreAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixFort pixfort Core pixfort-core allows Reflected XSS.This issue affects pixfort Core: from n/a through <= 3.2.22.
AplazadaMedia (6.3)0.27%—Pixfort CoreAI5/3/202617/6/2026
Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.
AplazadaMedia (5.9)0.33%💥 PoCInseriswiss Inseri CoreAI5/3/202617/6/2026
Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5.
AplazadaAlta (8.1)0.58%—Mikado-themes Topscore - Sports Wordpress ThemeAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2.
AplazadaCrítica (9.3)0.40%—Don-themes Riode CoreAI5/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind SQL Injection.This issue affects Riode Core: from n/a through <= 1.6.26.
AnalizadaAlta (8.2)1.0%—Underscorejs Underscore3/3/202617/6/2026
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be…
ModificadaBaja (2)0.60%—Erlang Rebar3HEXHEX Core27/2/202617/6/2026
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl,…