Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.21% | — | RTI Connext Professional | 30/4/2026 | 30/9/2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before… | |
| Aplazada | Media (4.3) | 0.16% | — | Pluginus Bear Bulk Editor AND Products Manager ProfessionalAI | 8/4/2026 | 24/7/2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for… | |
| Aplazada | Media (6.9) | 0.15% | — | Asprunner ProfessionalAI | 5/4/2026 | 24/7/2026 | ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash. | |
| Modificada | Alta (8.8) | 0.39% | — | RTI Connext Professional | 1/4/2026 | 22/9/2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup. This issue affects Connext… | |
| Modificada | Media (6.3) | 0.16% | — | RTI Connext Professional | 31/3/2026 | 22/9/2026 | Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x before 5.1.*. | |
| Aplazada | Alta (8.7) | 0.44% | — | Zkteco Zkaccess ProfessionalAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for… | |
| Aplazada | Alta (8.7) | 0.33% | — | Pelco Sarix Professional 3 SeriesAI | 26/2/2026 | 17/6/2026 | The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be accessed without proper authentication. This weakness can lead to unauthorized… | |
| Aplazada | Media (6.7) | 0.33% | — | Surfoffline ProfessionalAI | 12/2/2026 | 17/6/2026 | SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of… | |
| Aplazada | Alta (8.4) | 0.21% | — | Frigate ProfessionalAI | 30/1/2026 | 17/6/2026 | Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the 'Find Computer' feature that allows attackers to execute arbitrary code by overflowing the computer name input field. Attackers can craft a malicious payload that triggers a buffer overflow, enabling code execution and launching… | |
| Aplazada | Alta (8.4) | 0.18% | — | Socusoft Photo TO Video Converter ProfessionalAI | 30/1/2026 | 17/6/2026 | Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder' input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the output folder field to trigger a stack-based buffer overflow and… | |
| Aplazada | Alta (8.4) | 0.17% | — | Frigate ProfessionalAI | 29/1/2026 | 17/6/2026 | Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter… | |
| Aplazada | Alta (7.6) | 0.32% | — | Firestormplugins Firestorm Professional Real EstateAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through <= 2.7.11. | |
| Aplazada | Alta (8.5) | 0.15% | — | Brother Bradmin ProfessionalAI | 21/1/2026 | 17/6/2026 | Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allows local users to potentially execute arbitrary code. Attackers can place a malicious executable named 'BRAdmin' in the C:\Program Files (x86)\Brother\ directory to gain local system privileges. | |
| Modificada | Media (6.5) | 0.40% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. | |
| Modificada | Media (5.4) | 0.28% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed. | |
| Aplazada | Media (4.3) | 0.32% | — | Husky Products Filter ProfessionalAI | 18/12/2025 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.3 via the "woof_add_subscr" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.3) | 0.23% | — | RTI Connext Professional | 16/12/2025 | 22/9/2026 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.2.0 before 7.3.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Husky Products Filter ProfessionalAI | 3/12/2025 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.2 via the "woof_add_query" and "woof_remove_query" functions due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.35% | — | Husky Products Filter ProfessionalAI | 28/10/2025 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all versions up to, and including, 1.3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (7.1) | 0.32% | — | Workexaminer ProfessionalAI | 21/10/2025 | 17/6/2026 | All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This allows an attacker with access to the network to read the transmitted sensitive data. An attacker can also freely modify the data on the wire. The monitoring clients transmit their data to the server… | |
| Aplazada | Crítica (9.8) | 0.90% | — | Workexaminer ProfessionalAI | 21/10/2025 | 17/6/2026 | An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side authentication checks to bypass the login prompt in the WorkExaminer Professional console to gain administrative access to the WorkExaminer server and therefore all sensitive monitoring data. This… | |
| Aplazada | Alta (8.8) | 0.93% | — | Workexaminer Professional ServerAI | 21/10/2025 | 17/6/2026 | The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or read data, log files and gain remote code execution as NT… | |
| Aplazada | Media (4.3) | 0.13% | — | Professional Contact FormAI | 27/9/2025 | 17/6/2026 | The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the watch_for_contact_form_submit function. This makes it possible for unauthenticated attackers to trigger test email… | |
| Modificada | Media (5.8) | 0.21% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.5.0 before 7.6.0. | |
| Modificada | Alta (8.3) | 0.37% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*,… |