Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1919 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.91%—Wppa WP Photo Album PlusAI19/9/202621/9/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd()…
Pendiente de análisisAlta (7.7)1.5%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Pendiente de análisisAlta (7.5)1.1%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
AplazadaMedia (6.1)0.23%—Wordplus Better MessagesAI16/9/202618/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Pendiente de análisisMedia (6.9)0.26%—Nginx PlusAINginx Open SourceAIOpensslAI15/9/202618/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the…
AplazadaAlta (8.8)0.69%—Ruoyi-vue-plusAI15/9/202622/9/2026
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components
AplazadaMedia (5.3)0.41%—Xxyopen Novel-plusAI14/9/202623/9/2026
novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase…
AplazadaMedia (6.9)0.55%—Xxyopen Novel-plusAI14/9/202623/9/2026
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the…
AplazadaAlta (7.1)0.46%—Xxyopen Novel-plusAI14/9/202623/9/2026
novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email addresses and phone numbers for users within their data scope, enabling offline hash…
Pendiente de análisisAlta (8.5)0.11%—Logitech Logi Options PlusAI14/9/202618/9/2026
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
AplazadaAlta (7.2)0.29%—Wppa WP Photo Album PlusAI11/9/202611/9/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.33%—Dernekplus Website TemplateAI10/9/202610/9/2026
Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaMedia (4.3)0.42%—Ruoyi-cloud-plusAI9/9/202614/9/2026
In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details…
AplazadaMedia (6.9)0.64%—Seakee Cpa-manager-plusAI8/9/202611/9/2026
A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack…
AplazadaCrítica (9.8)0.74%—Slimkit Think SNS PlusAI4/9/20269/9/2026
An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component
AplazadaMedia (5.4)0.50%—Netgate Pfsense PlusAINetgate Pfsense CEAI4/9/202614/9/2026
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file
AplazadaMedia (5.4)0.28%—Netgate Pfsense PlusAINetgate Pfsense CEAI4/9/20269/9/2026
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated…
Pendiente de análisisMedia (5.1)1.1%—Pfsense PlusAIPfsense CEAI3/9/20269/9/2026
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value…
Pendiente de análisisMedia (5.1)1.1%—Pfsense PlusAIPfsense CEAI3/9/20269/9/2026
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML…
Pendiente de análisisMedia (5.1)1.1%—Pfsense PlusAIPfsense CEAI3/9/20269/9/2026
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resolution, start-date, end-date,…
Pendiente de análisisAlta (8.6)0.57%—Nginx PlusAINginx Gateway FabricAI2/9/20263/9/2026
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the…
Pendiente de análisisAlta (8.8)1.4%—Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI2/9/20268/9/2026
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
AplazadaAlta (8.7)0.19%—CP Plus Cp-xr-de21-sAI28/8/20261/9/2026
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the…
AplazadaMedia (5.9)0.14%—UpdraftplusAI27/8/202628/8/2026
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
AplazadaMedia (5.3)0.35%—Dromara Ruoyi-vue-plusAI21/8/202624/8/2026
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper authorization. The attack can be…