Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Awesometogi Awesome Event BookingAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through <= 2.7.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Metorik-helperAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metorik Metorik – Reports & Email Automation for WooCommerce metorik-helper allows Cross Site Request Forgery.This issue affects Metorik – Reports & Email Automation for WooCommerce: from n/a through <= 1.7.1. | |
| Aplazada | Media (5.3) | 0.44% | — | Awesometogi Product Category TreeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AWESOME TOGI Product Category Tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Category Tree: from n/a through 2.5. | |
| Aplazada | Alta (7.1) | 0.42% | — | Hometory Mang Board WPAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0. | |
| Modificada | Alta (8.8) | 0.27% | — | Awesometogi Product Category Tree | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | |
| Modificada | Media (6.1) | 0.33% | — | Awesometogi Product-category-tree | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | |
| Modificada | Media (5.9) | 0.95% | — | Bticino Door Entry FOR Hometouch | 6/2/2023 | 17/6/2026 | BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate. | |
| Modificada | Crítica (9.8) | 3.7% | — | Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+6 | 13/2/2020 | 17/6/2026 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie." | |
| Modificada | Crítica (9.8) | 2.7% | — | Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+6 | 13/2/2020 | 17/6/2026 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Globalsupergametoken Project Globalsupergametoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for GlobalSuperGameToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Extremetoken Project Extremetoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Extreme Coin (XT) (Contract Name: ExtremeToken), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aspindir Meto Forum | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp. | |
| Modificada | Media (4) | 1.9% | 💥 Exploit | Scott Metoyer RED Mombin | 3/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php. | |
| Modificada | Media (5) | 1.3% | — | Sherzod Ruzmetov CGI Session | 19/3/2006 | 16/6/2026 | CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite. | |
| Modificada | Alta (7.5) | 1.7% | — | Sherzod Ruzmetov CGI Session | 19/3/2006 | 16/6/2026 | CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files. |