Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 52% | 💥 Exploit | Nestjs Devtools-integration | 2/8/2025 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an… | |
| Aplazada | Media (6.5) | 0.20% | — | Mostafa Shahiri Simple Nested MenuAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu simple-nested-menu allows Stored XSS.This issue affects Simple Nested Menu: from n/a through <= 1.0. | |
| Analizada | Media (4.8) | 0.34% | — | Kylephillips Nested Pages | 15/5/2025 | 17/6/2026 | The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.39% | — | Emotionalonlinestorytelling Oracle Cards LiteAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite oracle-cards allows Reflected XSS.This issue affects Oracle Cards Lite: from n/a through <= 1.2.1. | |
| Analizada | Media (4.8) | 0.26% | — | Kylephillips Nested Pages | 23/3/2025 | 17/6/2026 | The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.5) | 0.34% | — | Nestjs Nest | 14/3/2025 | 17/6/2026 | File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header. | |
| Analizada | Crítica (9.1) | 0.37% | — | Sainwp Onestore Sites | 27/2/2025 | 17/6/2026 | The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query… | |
| Aplazada | Crítica (9.6) | 0.24% | — | Sainwp Onestore SitesAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1. | |
| Aplazada | Media (5.9) | 0.38% | — | Kylephillips Nested PagesAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages wp-nested-pages allows Stored XSS.This issue affects Nested Pages: from n/a through <= 3.2.9. | |
| Aplazada | Media (6.5) | 0.39% | — | Aboutorab Pourhaghani Persian Nested Showhide TextAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aboutorab Pourhaghani Persian Nested Show/Hide Text persian-nested-showhide-text allows Stored XSS.This issue affects Persian Nested Show/Hide Text: from n/a through <= 1.5. | |
| Analizada | Crítica (9.8) | 0.16% | — | Google Nest Doorbell (battery) FirmwareGoogle Nest CAM (outdoor OR Indoor, Battery) FirmwareGoogle Nest CAM With Floodlight FirmwareGoogle Nest CAM (indoor, Wired) Firmware | 2/10/2024 | 17/6/2026 | According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the… | |
| Analizada | Alta (8.7) | 0.69% | — | Netflix E2nest | 27/9/2024 | 17/6/2026 | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a | |
| Analizada | Media (5.3) | 0.15% | — | Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware | 16/9/2024 | 17/6/2026 | U-Boot environment is read from unauthenticated partition. | |
| Modificada | Media (5.9) | 0.19% | — | Google Nest Mini FirmwareHaxx Libcurl | 19/8/2024 | 17/6/2026 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through. | |
| Modificada | Alta (8.8) | 0.29% | — | Kylephillips Nested Pages | 4/7/2024 | 17/6/2026 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to call… | |
| Aplazada | Media (5.4) | 0.42% | — | Envisionware Computer Access AND Reservation Control SelfcheckAIEnvisionware OnestopAI | 24/6/2024 | 17/6/2026 | An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal. | |
| Analizada | Alta (7.7) | 0.24% | — | Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware | 5/4/2024 | 17/6/2026 | Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application | |
| Modificada | Crítica (9.8) | 0.18% | — | Google Nest Wifi PRO Firmware | 2/1/2024 | 17/6/2026 | Google Nest WiFi Pro root code-execution & user-data compromise | |
| Modificada | Crítica (9.8) | 0.24% | — | Google Nest Audio FirmwareGoogle Nest Mini FirmwareGoogle Home Mini FirmwareGoogle Home Firmware | 2/1/2024 | 17/6/2026 | An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege | |
| Modificada | Media (6.1) | 0.40% | — | Marzocca List ALL Posts BY Authors Nested Categories AND Titles | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10. | |
| Modificada | Media (4.8) | 0.39% | — | Kylephillips Nested Pages | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6. | |
| Modificada | Alta (8.8) | 0.11% | — | Google Nest HUB MAX FirmwareGoogle Nest HUB FirmwareGoogle Wifi FirmwareGoogle Nest Wifi Point Firmware+1 | 25/7/2023 | 17/6/2026 | There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on… | |
| Modificada | Media (6.1) | 0.36% | — | Bugfinder Minestack | 22/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier… | |
| Modificada | Media (4.3) | 0.39% | — | Ashstonestudios Advanced Popups | 12/7/2023 | 17/6/2026 | The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Media (6.1) | 0.36% | — | Onesttech Onest Customer Relation Management System | 4/7/2023 | 17/6/2026 | A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/project/update/2 of the component Project List Handler. The manipulation of the argument name with the input <script>alert(1)</script> leads to cross site scripting. It is possible to… |