Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Hogash KallyasAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hogash KALLYAS kallyas allows Cross Site Request Forgery.This issue affects KALLYAS: from n/a through < 4.25.0. | |
| Aplazada | Media (5.1) | 0.31% | — | Xcally OmnichannelAI | 13/11/2025 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user… | |
| Aplazada | Media (5.3) | 0.25% | — | Hogash KallyasAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. | |
| Aplazada | Crítica (9.9) | 0.39% | — | Hogash KallyasAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. | |
| Aplazada | Media (5.4) | 0.24% | — | Hogash KallyasAI | 6/11/2025 | 5/10/2026 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. | |
| Aplazada | Alta (8.8) | 0.58% | — | KallyasAI | 1/11/2025 | 17/6/2026 | The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. This is due to the theme not restricting access to the code editor widget for non-administrators. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.19% | — | KallyasAI | 1/11/2025 | 17/6/2026 | The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.20% | — | AllyAI | 16/10/2025 | 17/6/2026 | The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable… | |
| Aplazada | Alta (7.5) | 0.43% | — | Dynamically Display PostsAI | 15/10/2025 | 1/10/2026 | The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including, 1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Creedallyinc Bulk Featured ImageAI | 5/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.5) | 0.82% | — | KallyasAI | 26/7/2025 | 17/6/2026 | The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the… | |
| Aplazada | Alta (8.1) | 0.44% | — | KallyasAI | 26/7/2025 | 17/6/2026 | The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up to, and including, 4.21.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders on the… | |
| Aplazada | Media (5.3) | 0.30% | — | Siemens TIA Project-serverAISiemens Totally Integrated Automation PortalAI | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19… | |
| Aplazada | Crítica (9.1) | 0.38% | — | Creedallyinc Bulk Featured ImageAI | 4/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Aplazada | Media (6.5) | 0.23% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9. | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation PortalSiemens User Management Component | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Aplazada | Media (5.9) | 0.27% | — | Jonashjalmarsson Really Simple Under Construction PageAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson Really Simple Under Construction Page really-simple-under-construction allows Stored XSS.This issue affects Really Simple Under Construction Page: from n/a through <= 1.4.6. | |
| Aplazada | Media (4.3) | 0.38% | — | Creedally Bulk Featured ImageAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |
| Aplazada | Media (5.9) | 0.36% | — | Elementor AllyAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Ally pojo-accessibility allows Stored XSS.This issue affects Ally: from n/a through <= 3.1.0. | |
| Aplazada | Alta (7.8) | 0.19% | — | Tally Prime Edit LOGAI | 7/2/2025 | 17/6/2026 | Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL. | |
| Aplazada | Media (6.4) | 0.34% | — | Automatically Hierarchic Categories IN MenuAI | 30/1/2025 | 17/6/2026 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.20% | — | Really-simple-plugins Really Simple SSLAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Cross Site Request Forgery.This issue affects Really Simple SSL: from n/a through <= 9.1.4. | |
| Aplazada | Alta (7.1) | 0.23% | — | Rally Vincent BauernregelnAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rally Vincent Bauernregeln bauernregeln allows Reflected XSS.This issue affects Bauernregeln: from n/a through <= 1.0.1. |