Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.34% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a… | |
| Analizada | Alta (7.5) | 0.46% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to… | |
| Analizada | Baja (3.7) | 0.26% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator.… | |
| Analizada | Media (5.3) | 0.29% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpexperts Post SmtpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions. | |
| Analizada | Alta (7.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 9/6/2026 | 20/7/2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. | |
| Analizada | Media (6.8) | 0.20% | — | Schneider-electric Ecostruxure Machine Expert Hvac | 14/5/2026 | 17/6/2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. | |
| Aplazada | Alta (8.5) | 0.36% | — | Saad Iqbal Apiexperts Square FOR WoocommerceAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1. | |
| Analizada | Media (5.1) | 0.26% | — | Dragonexpert Recent Threads ON Index | 29/4/2026 | 17/6/2026 | MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing… | |
| Analizada | Media (5.3) | 0.42% | — | Fastapiexpert Python-multipart | 18/4/2026 | 17/6/2026 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing… | |
| Aplazada | Media (4.4) | 0.33% | — | Experto DashboardAI | 9/4/2026 | 24/7/2026 | The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versions up to and including… | |
| Analizada | Alta (8.8) | 0.46% | — | Phpscriptsmall ASK Expert Script | 5/4/2026 | 24/7/2026 | Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in… | |
| Aplazada | Media (6.5) | 0.33% | — | Wpexperts NEW User ApproveAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.3. | |
| Aplazada | Alta (7.2) | 0.39% | — | Wpexperts Post SmtpAI | 18/3/2026 | 17/6/2026 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpexperts Post SmtpAI | 18/3/2026 | 17/6/2026 | The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or… | |
| Analizada | Crítica (9.1) | 0.18% | — | IBM DB2 Recovery Expert | 17/3/2026 | 17/6/2026 | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission. | |
| Analizada | Alta (7.2) | 0.23% | — | Schneider-electric Ecostruxure Automation Expert | 10/3/2026 | 23/6/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Analizada | Crítica (9.3) | 0.55% | — | Changingtec Idexpert | 2/3/2026 | 17/6/2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them. | |
| Analizada | Crítica (9.3) | 0.55% | — | Changingtec Idexpert | 2/3/2026 | 17/6/2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them. | |
| Aplazada | Alta (8.6) | 0.27% | — | Wpexperts NEW User ApproveAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.0. | |
| Analizada | Media (6.5) | 0.12% | — | IBM DB2 Recovery Expert | 17/2/2026 | 17/6/2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Media (5.9) | 0.14% | — | IBM DB2 Recovery Expert | 17/2/2026 | 17/6/2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (6.5) | 0.18% | — | IBM DB2 Recovery Expert | 17/2/2026 | 17/6/2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site… | |
| Analizada | Media (6.1) | 0.14% | — | IBM DB2 Recovery Expert | 17/2/2026 | 17/6/2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web… |