Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.46% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Media (5.4) | 0.41% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Analizada | Alta (7.2) | 0.64% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Aplazada | Alta (8.5) | 0.36% | — | Thememove UnicampAI | 2/7/2026 | 6/10/2026 | Subscriber SQL Injection in Unicamp <= 2.2.2 versions. | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Aplazada | Media (4.3) | 0.19% | — | Remove Nofollow Commenter URLAI | 2/6/2026 | 22/7/2026 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's… | |
| Aplazada | Media (4.3) | 0.20% | — | Remove Meta Boxes PER User RoleAI | 2/6/2026 | 22/7/2026 | The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset… | |
| Aplazada | Media (4.3) | 0.27% | — | Prasadkirpekar WP Meta AND Date RemoverAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6. | |
| Analizada | Alta (7.5) | 0.45% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (7.5) | 0.34% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (7.5) | 0.43% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Aplazada | Media (4.3) | 0.19% | — | Remove Yellow BgboxAI | 20/5/2026 | 23/7/2026 | The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_api_settings' page. This makes it possible for unauthenticated attackers to reset the plugin's stored settings by… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (6.4) | 0.19% | — | Nextmove Lite Thank YOU Page WoocommerceAI | 2/5/2026 | 17/6/2026 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (8.8) | 0.50% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Aplazada | Alta (7.5) | 0.30% | — | Xlplugins Nextmove LiteAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Remove Post Type SlugAI | 19/2/2026 | 17/6/2026 | The Remove Post Type Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to incorrect nonce validation logic that uses OR (||) instead of AND (&&), causing the validation to fail when the nonce field is not empty OR when verification fails,… | |
| Aplazada | Alta (7.5) | 0.35% | — | Thememove UnicampAI | 3/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1. | |
| Aplazada | Media (5.3) | 0.35% | — | Xlplugins Nextmove LiteAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0. | |
| Aplazada | Alta (8.1) | 0.47% | — | Ancoathemes MovemeAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MoveMe moveme allows PHP Local File Inclusion.This issue affects MoveMe: from n/a through <= 1.2.15. | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR Objectscale*Progress ECS Connection ManagerProgress LoadmasterProgress Moveit WAF+1 | 13/1/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters |