Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1213 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.46% | — | ALL IN ONE WP Migration AND BackupAI | 16/8/2026 | 26/8/2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network. | |
| Aplazada | Media (6.5) | 0.51% | — | Backupbliss Backup MigrationAI | 15/8/2026 | 26/8/2026 | The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Everest BackupAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | |
| Aplazada | Alta (7.2) | 3.0% | — | Backupbliss Backup MigrationAI | 5/8/2026 | 12/8/2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell… | |
| Aplazada | Alta (8.5) | 0.17% | — | Asustor Backup PlanAIAsustor EzsyncAI | 4/8/2026 | 3/9/2026 | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local user can recover the key and forge valid… | |
| Aplazada | Media (4.9) | 0.44% | — | Wpvivid Backup MigrationAI | 1/8/2026 | 12/8/2026 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in… | |
| Aplazada | Media (6.5) | 0.51% | — | Pcloud WP BackupAI | 17/7/2026 | 17/7/2026 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup… | |
| Aplazada | Media (6.7) | 0.72% | — | Nocobase Plugin BackupsAIPostgresqlAI | 15/7/2026 | 18/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js… | |
| Aplazada | Media (4.4) | 0.24% | — | Wpvivid Backup FOR MainwpAI | 10/7/2026 | 10/7/2026 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Media (6.9) | 0.74% | — | Vinchin Backup AND RecoveryAI | 9/7/2026 | 10/7/2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and… | |
| Aplazada | Media (6.9) | 0.64% | — | Vinchin Backup & RecoveryAI | 9/7/2026 | 10/7/2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet… | |
| Aplazada | Media (6.5) | 0.47% | — | Wptimecapsule Backup AND Staging BY WP Time CapsuleAI | 9/7/2026 | 9/7/2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the… | |
| Aplazada | Alta (7.1) | 0.16% | — | Pcloud WP BackupAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. | |
| Aplazada | Alta (7.2) | 2.7% | — | Wpseeds WP Database BackupAI | 2/7/2026 | 2/7/2026 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into… | |
| Aplazada | Alta (7.5) | 0.39% | — | Trinity BackupAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions. | |
| Analizada | Alta (8.8) | 5.5% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… | |
| Analizada | Alta (8.8) | 0.94% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (8.8) | 0.95% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… | |
| Analizada | Alta (8.8) | 0.94% | — | Quest Netvault Backup | 25/6/2026 | 26/6/2026 | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… |