Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Awesometogi Awesome Event BookingAI31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through <= 2.7.1.
AplazadaMedia (4.3)0.19%—Metorik-helperAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Metorik Metorik – Reports & Email Automation for WooCommerce metorik-helper allows Cross Site Request Forgery.This issue affects Metorik – Reports & Email Automation for WooCommerce: from n/a through <= 1.7.1.
AplazadaMedia (5.3)0.44%—Awesometogi Product Category TreeAI9/12/202417/6/2026
Missing Authorization vulnerability in AWESOME TOGI Product Category Tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Category Tree: from n/a through 2.5.
AplazadaAlta (7.1)0.42%—Hometory Mang Board WPAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0.
ModificadaAlta (8.8)0.27%—Awesometogi Product Category Tree25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.
ModificadaMedia (6.1)0.33%—Awesometogi Product-category-tree18/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.
ModificadaMedia (5.9)0.95%—Bticino Door Entry FOR Hometouch6/2/202317/6/2026
BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.
ModificadaCrítica (9.8)3.7%—Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+613/2/202017/6/2026
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
ModificadaCrítica (9.8)2.7%—Timetoolsltd Sr9850 FirmwareTimetoolsltd Sr9750 FirmwareTimetoolsltd Sc9705 FirmwareTimetoolsltd Sr9210 Firmware+613/2/202017/6/2026
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
ModificadaAlta (7.5)1.1%—Globalsupergametoken Project Globalsupergametoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for GlobalSuperGameToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)0.99%—Extremetoken Project Extremetoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for Extreme Coin (XT) (Contract Name: ExtremeToken), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)2.3%💥 ExploitAspindir Meto Forum27/5/200816/6/2026
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.
ModificadaMedia (4)1.9%💥 ExploitScott Metoyer RED Mombin3/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.
ModificadaMedia (5)1.3%—Sherzod Ruzmetov CGI Session19/3/200616/6/2026
CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.
ModificadaAlta (7.5)1.7%—Sherzod Ruzmetov CGI Session19/3/200616/6/2026
CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.
Orbitaley — Vulnerabilidades