Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)52%💥 ExploitNestjs Devtools-integration2/8/202517/6/2026
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an…
AplazadaMedia (6.5)0.20%—Mostafa Shahiri Simple Nested MenuAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu simple-nested-menu allows Stored XSS.This issue affects Simple Nested Menu: from n/a through <= 1.0.
AnalizadaMedia (4.8)0.34%—Kylephillips Nested Pages15/5/202517/6/2026
The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaAlta (7.1)0.39%—Emotionalonlinestorytelling Oracle Cards LiteAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite oracle-cards allows Reflected XSS.This issue affects Oracle Cards Lite: from n/a through <= 1.2.1.
AnalizadaMedia (4.8)0.26%—Kylephillips Nested Pages23/3/202517/6/2026
The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (5.5)0.34%—Nestjs Nest14/3/202517/6/2026
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
AnalizadaCrítica (9.1)0.37%—Sainwp Onestore Sites27/2/202517/6/2026
The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query…
AplazadaCrítica (9.6)0.24%—Sainwp Onestore SitesAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1.
AplazadaMedia (5.9)0.38%—Kylephillips Nested PagesAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages wp-nested-pages allows Stored XSS.This issue affects Nested Pages: from n/a through <= 3.2.9.
AplazadaMedia (6.5)0.39%—Aboutorab Pourhaghani Persian Nested Showhide TextAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aboutorab Pourhaghani Persian Nested Show/Hide Text persian-nested-showhide-text allows Stored XSS.This issue affects Persian Nested Show/Hide Text: from n/a through <= 1.5.
AnalizadaCrítica (9.8)0.16%—Google Nest Doorbell (battery) FirmwareGoogle Nest CAM (outdoor OR Indoor, Battery) FirmwareGoogle Nest CAM With Floodlight FirmwareGoogle Nest CAM (indoor, Wired) Firmware2/10/202417/6/2026
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the…
AnalizadaAlta (8.7)0.69%—Netflix E2nest27/9/202417/6/2026
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
AnalizadaMedia (5.3)0.15%—Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware16/9/202417/6/2026
U-Boot environment is read from unauthenticated partition.
ModificadaMedia (5.9)0.19%—Google Nest Mini FirmwareHaxx Libcurl19/8/202417/6/2026
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
ModificadaAlta (8.8)0.29%—Kylephillips Nested Pages4/7/202417/6/2026
The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to call…
AplazadaMedia (5.4)0.42%—Envisionware Computer Access AND Reservation Control SelfcheckAIEnvisionware OnestopAI24/6/202417/6/2026
An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal.
AnalizadaAlta (7.7)0.24%—Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware5/4/202417/6/2026
Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application
ModificadaCrítica (9.8)0.18%—Google Nest Wifi PRO Firmware2/1/202417/6/2026
Google Nest WiFi Pro root code-execution & user-data compromise
ModificadaCrítica (9.8)0.24%—Google Nest Audio FirmwareGoogle Nest Mini FirmwareGoogle Home Mini FirmwareGoogle Home Firmware2/1/202417/6/2026
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
ModificadaMedia (6.1)0.40%—Marzocca List ALL Posts BY Authors Nested Categories AND Titles15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10.
ModificadaMedia (4.8)0.39%—Kylephillips Nested Pages14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.
ModificadaAlta (8.8)0.11%—Google Nest HUB MAX FirmwareGoogle Nest HUB FirmwareGoogle Wifi FirmwareGoogle Nest Wifi Point Firmware+125/7/202317/6/2026
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on…
ModificadaMedia (6.1)0.36%—Bugfinder Minestack22/7/202317/6/2026
A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier…
ModificadaMedia (4.3)0.39%—Ashstonestudios Advanced Popups12/7/202317/6/2026
The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted…
ModificadaMedia (6.1)0.36%—Onesttech Onest Customer Relation Management System4/7/202317/6/2026
A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/project/update/2 of the component Project List Handler. The manipulation of the argument name with the input <script>alert(1)</script> leads to cross site scripting. It is possible to…
Orbitaley — Vulnerabilidades