Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.20% | — | Astral UVAI | 8/8/2025 | 17/6/2026 | uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the archive's central directory. An attacker could contrive a ZIP archive that would extract with legitimate contents on some… | |
| Aplazada | Media (5.3) | 0.49% | — | Webprotect.ai Astra Security SuiteAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WebProtect.ai Astra Security Suite getastra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Astra Security Suite: from n/a through <= 0.2. | |
| Aplazada | Media (4.3) | 0.21% | — | Brainstormforce Astra-sitesAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Request Forgery.This issue affects Starter Templates: from n/a through <= 4.4.9. | |
| Modificada | Media (5.4) | 0.30% | — | Brainstormforce Astra Widgets | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.15. | |
| Aplazada | Media (6.5) | 0.25% | — | Fast Themes Sastra Essential Addons FOR ElementorAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fast Themes Sastra Essential Addons for Elementor sastra-essential-addons-for-elementor allows DOM-Based XSS.This issue affects Sastra Essential Addons for Elementor: from n/a through <= 1.0.5. | |
| Modificada | Media (5.4) | 0.25% | — | Brainstormforce Astra Widgets | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.14. | |
| Analizada | Alta (7.3) | 0.24% | — | Siemens Simcenter Nastran | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is vulnerable to memory corruption while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of… | |
| Analizada | Media (5.3) | 0.38% | — | Getastra WP Hardening | 18/9/2024 | 17/6/2026 | The WP Hardening – Fix Your WordPress Security plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 1.2.6. This is due to use of an incorrect regular expression within the "Stop User Enumeration" feature. This makes it possible for unauthenticated attackers to bypass… | |
| Analizada | Media (5.4) | 0.29% | — | Blueastral Page Builder\ | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42. | |
| Modificada | Media (4.8) | 0.32% | — | Blueastral Page Builder\ | 21/6/2024 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Modificada | Alta (8.8) | 0.39% | — | Brainstormforce Astra | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7. | |
| Analizada | Alta (7.3) | 0.23% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process. | |
| Aplazada | Media (6.4) | 0.35% | — | Brainstormforce AstraAI | 9/4/2024 | 17/6/2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary… | |
| Aplazada | Media (5.9) | 0.36% | — | Brainstormforce AstraAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4. | |
| Analizada | Crítica (9.8) | 0.50% | — | MongodbNetapp Astra Control CenterNetapp Ontap Tools | 7/3/2024 | 17/6/2026 | Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate… | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Nodejs Node.jsNetapp Astra Control Center | 20/2/2024 | 17/6/2026 | A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The… | |
| Modificada | Media (5.4) | 0.31% | — | Blueastral Page Builder\ | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23. | |
| Modificada | Alta (7.2) | 0.50% | — | Blueastral Page Builder\ | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25. | |
| Modificada | Alta (8.8) | 0.66% | — | Brainstormforce Astra | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1. | |
| Modificada | Alta (7.2) | 0.72% | — | Adastracrypto Cryptocurrency Payment & Donation BOX | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adastra Crypto Cryptocurrency Payment & Donation Box – Accept Payments in any Cryptocurrency on your WP Site for Free.This issue affects Cryptocurrency Payment & Donation Box – Accept Payments in any Cryptocurrency on… | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Golang GOGolang Http2Fedoraproject FedoraNetapp Astra Trident+1 | 11/10/2023 | 17/6/2026 | A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Media (5.4) | 0.39% | — | Blueastral Page Builder\ | 21/2/2023 | 17/6/2026 | The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.1) | 0.33% | — | Fastrack Reflex 2.0 Firmware | 26/12/2022 | 17/6/2026 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature. | |
| Modificada | Alta (7.5) | 0.86% | — | Fastrack Reflex 2.0 Firmware | 26/12/2022 | 17/6/2026 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a characteristic value. |