Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | InteractivecalculatorAI | 18/2/2026 | 17/6/2026 | The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interactivecalculator' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Baja (3.1) | 0.24% | — | Tanium Interact | 5/2/2026 | 17/6/2026 | Tanium addressed an improper access controls vulnerability in Interact. | |
| Analizada | Media (4.3) | 0.25% | — | Tanium Interact | 29/1/2026 | 17/6/2026 | Tanium addressed an improper access controls vulnerability in Interact. | |
| Aplazada | Media (6.4) | 0.24% | — | InteractionsAI | 28/1/2026 | 17/6/2026 | The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event selectors in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Aplazada | Media (4.3) | 0.26% | — | Qodeinteractive WanderlandAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5. | |
| Aplazada | Media (5.4) | 0.27% | — | Qodeinteractive CurlyAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3. | |
| Aplazada | Alta (8.1) | 0.59% | — | Qodeinteractive PowerliftAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Aplazada | Media (4.3) | 0.30% | — | Qodeinteractive BardAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229. | |
| Aplazada | Alta (7.1) | 0.28% | — | Highwarden Super Interactive MapsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Interactive Maps super-interactive-maps allows Reflected XSS.This issue affects Super Interactive Maps: from n/a through <= 2.3. | |
| Aplazada | Alta (8.5) | 0.15% | — | Luidia Ebeam Interactive SuiteAI | 21/1/2026 | 17/6/2026 | eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Luidia\eBeam Stylus Driver\ to inject malicious executables that… | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Hendon | 8/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP Local File Inclusion.This issue affects Hendon: from n/a through < 1.7. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Curly | 8/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.This issue affects Curly: from n/a through < 3.3. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Optimize | 8/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Wellspring | 8/1/2026 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring allows PHP Local File Inclusion.This issue affects Wellspring: from n/a through < 2.8. | |
| Modificada | Alta (8.1) | 0.39% | — | Qodeinteractive Lekker | 30/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8. | |
| Modificada | Media (5.4) | 0.22% | — | Qodeinteractive Fivestar | 30/12/2025 | 5/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiveStar: from n/a through <= 1.7. | |
| Modificada | Media (5.4) | 0.22% | — | Qodeinteractive Backpack Traveler | 30/12/2025 | 5/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Creativeinteractivemedia Real3d-flipbook-liteAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4. | |
| Modificada | Media (4.3) | 0.28% | — | Qodeinteractive Powerlift | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Modificada | Alta (8.8) | 0.45% | — | Qodeinteractive Wilmer | 9/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.5. | |
| Analizada | Alta (8.7) | 2.8% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateLicense.php. When a license file is uploaded, the application derives a new filename by combining a… | |
| Analizada | Alta (8.7) | 3.4% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php. When a fax "send" test is requested, the application builds a faxsender command line using… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT… | |
| Analizada | Alta (8.5) | 0.20% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through… |