Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)0.39%—Uptime KumaAI17/3/202517/6/2026
Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.
AplazadaMedia (4.3)0.17%—Rajesh Kumar WP Bulk Post DuplicatorAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator wp-bulk-post-duplicator allows Cross Site Request Forgery.This issue affects WP Bulk Post Duplicator: from n/a through <= 1.2.
AplazadaAlta (7.1)0.16%—Nirmal Kumar RAM WP Social StreamAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nirmal Kumar Ram WP Social Stream wp-social-stream allows Stored XSS.This issue affects WP Social Stream: from n/a through <= 1.1.
AplazadaAlta (7.1)0.33%—Hkharpreetkumar1 AIO ShortcodesAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 AIO Shortcodes aio-shortcodes allows Stored XSS.This issue affects AIO Shortcodes: from n/a through <= 1.3.
AplazadaAlta (7.1)0.19%—Ravi Kumar Vanukuru RSV GmapsAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ravi Kumar Vanukuru RSV GMaps rsv-google-maps allows Stored XSS.This issue affects RSV GMaps: from n/a through <= 1.5.
AplazadaMedia (6.5)0.23%—Vicky Kumar Coupon-liteAI31/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicky Kumar Coupon coupon-lite allows DOM-Based XSS.This issue affects Coupon: from n/a through <= 1.2.2.
AplazadaMedia (6.8)1.8%💥 PoCUptime KumaAI20/12/202417/6/2026
Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server by exploiting the `file:///` protocol. This vulnerability is triggered via the **"real-browser"** request type, which takes a screenshot of the URL…
AplazadaCrítica (9.3)0.75%💥 PoCRobindkumar Wr-age-verificationAI16/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0.
AplazadaAlta (8.5)0.52%—Robindkumar Wr-age-verificationAI16/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age Verification wr-age-verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through <= 2.0.0.
AplazadaMedia (6.5)0.32%—Ravi Kumar Vanukuru RSV 360 ViewAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ravi Kumar Vanukuru RSV 360 View rsv-360-view allows DOM-Based XSS.This issue affects RSV 360 View: from n/a through <= 1.0.
AplazadaMedia (6.5)0.32%—Ravi Kumar Vanukuru RSV PDF PreviewAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ravi Kumar Vanukuru RSV PDF Preview rsv-pdf-preview allows Stored XSS.This issue affects RSV PDF Preview: from n/a through <= 1.0.
ModificadaMedia (6.1)0.16%—Sureshkumar Wp-login Customizer18/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.This issue affects wp-login customizer: from n/a through <= 1.0.
AnalizadaMedia (5.1)0.41%—Anujkumar Hospital Management System5/11/202417/6/2026
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.1)0.41%—Anujkumar Hospital Management System5/11/202417/6/2026
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be initiated remotely. The…
AplazadaAlta (8.8)0.47%—KumaAI25/7/202417/6/2026
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
AplazadaMedia (5.9)0.32%—Varun Kumar Easy LogoAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Varun Kumar Easy Logo allows Stored XSS.This issue affects Easy Logo: from n/a through 1.9.3.
ModificadaAlta (7.5)0.69%—Kumaf Pyhtml2pdf20/2/202417/6/2026
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
ModificadaAlta (8.8)0.38%—Dockge.kuma DockgeUptime.kuma Uptime Kuma11/12/202317/6/2026
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the application on behalf of their client. When connecting to the server using…
ModificadaAlta (7.8)0.26%—Dockge.kuma DockgeUptime.kuma Uptime Kuma11/12/202317/6/2026
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or browser restarts. This vulnerability…
ModificadaMedia (6.1)0.50%—Uptime.kuma Uptime Kuma1/12/202317/6/2026
Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google Analytics ID and the template has not been sanitized, there is an…
ModificadaMedia (5.4)0.42%—Sureshkumarmukhiya Anywhere Flash Embed22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh KUMAR Mukhiya Anywhere Flash Embed plugin <= 1.0.5 versions.
ModificadaAlta (7.8)0.27%—Uptime.kuma Uptime Kuma9/10/202317/6/2026
Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.
ModificadaAlta (7.5)1.3%—Vinitkumar Json2xml22/8/202317/6/2026
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
ModificadaAlta (8.1)1.2%—Uptime-kuma Project Uptime-kuma5/7/202317/6/2026
Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after…
ModificadaAlta (8.8)2.0%—Uptime-kuma Project Uptime-kuma5/7/202317/6/2026
Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code execution. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in…
Orbitaley — Vulnerabilidades