Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.23% | — | Openfga Helm ChartsOpenfga | 22/4/2026 | 17/6/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for a subsequent… | |
| Aplazada | Media (6.4) | 0.33% | — | Power Charts LiteAI | 15/4/2026 | 17/6/2026 | The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions up to, and including, 0.1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute. Specifically, in the pc_shortcode()… | |
| Analizada | Alta (8.8) | 0.27% | — | Openfga Helm ChartsOpenfga | 6/4/2026 | 24/7/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.… | |
| Aplazada | Alta (7.1) | 0.20% | — | Artstudioworks BrooksideAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.This issue affects Brookside: from n/a through 1.4. | |
| Aplazada | Media (5.3) | 0.32% | — | Webgeniuslab BigheartsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebGeniusLab BigHearts bighearts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BigHearts: from n/a through <= 3.1.14. | |
| Aplazada | Alta (8.4) | 0.14% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege. | |
| Aplazada | Alta (8.5) | 0.11% | — | Digital Arts Finalcode ClientAI | 26/2/2026 | 17/6/2026 | The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Baja (3.7) | 0.38% | — | Enocean Smartserver IOTAI | 20/2/2026 | 17/6/2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory. | |
| Aplazada | Alta (8.1) | 0.91% | — | Enocean Smartserver IOTAI | 20/2/2026 | 17/6/2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device. | |
| Aplazada | Media (6.4) | 0.28% | — | SmartsuppAI | 19/2/2026 | 17/6/2026 | The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.8) | 0.35% | — | Openfga Helm ChartsOpenfga | 6/2/2026 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable to improper policy enforcement when certain Check calls are executed.… | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Smartseo | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.12. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Heartstar | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows PHP Local File Inclusion.This issue affects HeartStar: from n/a through <= 1.0.14. | |
| Aplazada | Baja (1.9) | 0.20% | — | Smartbit Commv SmartschoolAI | 15/12/2025 | 17/6/2026 | A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component be.smartschool.mobile.SplashActivity. Executing manipulation can lead to path traversal. The attack requires local access. The exploit has been published and may be used. The vendor was contacted… | |
| Analizada | Media (5.8) | 0.29% | — | Openfga Helm ChartsOpenfga | 21/11/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject… | |
| Modificada | Alta (8.5) | 0.31% | — | Axiomthemes Smartseo | 6/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: from n/a through <= 4.0. | |
| Aplazada | Alta (7.1) | 0.23% | — | Wpinstinct Woo-vehicle-parts-finderAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpinstinct WOO Vehicle Parts FinderAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Thememove Learts AddonsAI | 22/10/2025 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from n/a through < 1.7.5. | |
| Aplazada | Media (5.5) | 0.22% | — | Interactive Human Anatomy With Clickable Body PartsAI | 3/10/2025 | 17/6/2026 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Media (6.5) | 0.38% | — | Vitaracharts | 2/10/2025 | 5/7/2026 | VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp. | |
| Aplazada | Baja (2.3) | 0.24% | — | SmartstoreAI | 22/9/2025 | 17/6/2026 | A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /checkout/confirm/ of the component Gift Voucher Handler. The manipulation leads to race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Media (5.3) | 0.31% | — | Mahmudul Hasan Arif Ninja ChartsAI | 5/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Mahmudul Hasan Arif Ninja Charts ninja-charts allows Retrieve Embedded Sensitive Data.This issue affects Ninja Charts: from n/a through <= 3.3.5. | |
| Aplazada | Media (6.1) | 0.32% | — | Asian Arts Talents Foundation Aatf WebsiteAI | 2/9/2025 | 17/6/2026 | Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to… | |
| Analizada | Crítica (9.8) | 0.83% | — | Vishalmathur Online Artwork AND Fine Arts Project | 20/8/2025 | 17/6/2026 | A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution. |