Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 7.1% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It… | |
| Analizada | Media (5.5) | 2.0% | 💥 Exploit | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Media (5.5) | 6.1% | — | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The… | |
| Analizada | Alta (8.9) | 6.9% | — | Sangfor Operation AND Maintenance Security Management System | 9/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The… | |
| Analizada | Alta (8.9) | 6.1% | — | Sangfor Operation AND Maintenance Management System | 9/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may… | |
| Analizada | Alta (7.4) | 5.7% | — | Sangfor Operation AND Maintenance Management System | 9/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.17% | — | Conditional Maintenance ModeAI | 25/11/2025 | 17/6/2026 | The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation when toggling the maintenance mode status. This makes it possible for unauthenticated attackers to enable or disable the… | |
| Analizada | Baja (2.1) | 5.1% | 💥 PoC | Sangfor Operation AND Maintenance Security Management System | 9/11/2025 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.20% | — | Zucchetti Infinity ZmaintenanceInfinity Zucchetti | 4/11/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Anheng Mingyu Operation AND Maintenance Audit AND Risk Control SystemAI | 30/10/2025 | 17/6/2026 | Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints… | |
| Aplazada | Baja (3.5) | 0.18% | — | NS Maintenance ModeAI | 30/10/2025 | 17/6/2026 | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.3) | 0.25% | — | NS Maintenance ModeAI | 22/10/2025 | 17/6/2026 | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address | |
| Analizada | Media (5.4) | 0.18% | — | Oracle Peoplesoft Enterprise FIN Maintenance Management | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN… | |
| Aplazada | Media (4.3) | 0.16% | — | Wp-buy Wp-maintenance-mode-site-under-constructionAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction wp-maintenance-mode-site-under-construction allows Cross Site Request Forgery.This issue affects WP Maintenance Mode & Site Under Construction: from n/a through <= 4.3. | |
| Aplazada | Alta (7.2) | 0.53% | — | Florent Maillefaud WP MaintenanceAI | 7/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Injection.This issue affects WP Maintenance: from n/a through <= 6.1.9.7. | |
| Aplazada | Alta (7.5) | 0.57% | — | PHPAIAwplife Coming Soon Maintenance ModeAI | 15/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mobeen Abdullah Coming Soon, Maintenance Mode site-mode allows PHP Local File Inclusion.This issue affects Coming Soon, Maintenance Mode: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.1) | 0.67% | 💥 PoC | Niteothemes CMP Coming Soon MaintenanceAI | 4/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14. | |
| Aplazada | Alta (8.1) | 1.3% | — | Countdown Coming Soon Maintenance Countdown ClockAI | 4/4/2025 | 17/6/2026 | The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server,… | |
| Analizada | Baja (3.5) | 0.28% | — | Brijeshk89 Smart Maintenance Mode | 26/3/2025 | 17/6/2026 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.1) | 0.32% | — | Brijeshk89 Smart Maintenance ModeAI | 26/3/2025 | 17/6/2026 | The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.27% | — | Brijeshk89 Smart Maintenance Mode | 25/3/2025 | 17/6/2026 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.8) | 0.46% | — | EBM Technologies EBM Maintenance CenterAI | 21/3/2025 | 17/6/2026 | EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Modificada | Alta (8.8) | 0.19% | — | Codevibrant Maintenance Notice | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue affects Maintenance Notice: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.1) | 0.14% | — | Gmnazmul Smart-maintenance-countdownAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue affects Smart Maintenance & Countdown: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.16% | — | Seedprod Coming Soon Page Under Construction AND Maintenance ModeAI | 27/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Cross Site Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.18.9. |