Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.50%—Broadcom BitnamiBroadcom Bitnami/pgpool13/5/202517/6/2026
The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'repmgr' user that allows unauthenticated access to the database inside the cluster. The PGPOOL_SR_CHECK_USER is the user that Pgpool itself uses to perform streaming replication checks against nodes,…
AplazadaAlta (7.6)0.63%—Wppool FlexstockAI27/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock stock-sync-with-google-sheet-for-woocommerce allows Blind SQL Injection.This issue affects FlexStock: from n/a through <= 3.13.1.
AplazadaMedia (4.3)0.20%—Antoineh Football PoolAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forgery.This issue affects Football Pool: from n/a through <= 2.12.2.
AplazadaAlta (7.5)0.53%—Pgpool-iiAI12/9/202417/6/2026
Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved.
AplazadaMedia (6.5)0.26%—Antoineh Football PoolAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.9.
AplazadaMedia (5.9)0.27%—Antoineh Football PoolAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.10.
ModificadaMedia (6.9)0.74%—Janobe Pool OF Bethesda Online Reservation System27/6/202417/6/2026
A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument rmtype_id leads to sql injection. The attack may be launched remotely. The…
ModificadaMedia (6.9)0.65%—Janobe Pool OF Bethesda Online Reservation System18/6/202417/6/2026
A vulnerability classified as critical was found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument log_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.9)0.68%—Janobe Pool OF Bethesda Online Reservation System18/6/202417/6/2026
A vulnerability classified as critical has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.9)0.87%—Janobe Pool OF Bethesda Online Reservation System18/6/202417/6/2026
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is the function uploadImage of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The…
ModificadaMedia (4.3)0.34%—Wppool WP Dark Mode6/6/202417/6/2026
The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdm_social_share_save_options function in all versions up to, and including, 5.0.4. This…
AplazadaMedia (5.9)0.36%—Wppool Sheets TO WP Table Live SyncAI6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0.
AplazadaMedia (6.2)0.18%—Spidernet-io SpiderpoolAI1/5/202417/6/2026
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
AplazadaMedia (6.5)0.36%—Wppool Webinar AND Video Conference With Jitsi MeetAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Webinar and Video Conference with Jitsi Meet allows Stored XSS.This issue affects Webinar and Video Conference with Jitsi Meet: from n/a through 2.6.3.
AplazadaMedia (6.5)0.36%—Antoineh Football PoolAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.3.
ModificadaAlta (8.8)0.30%—Wppool Sheets TO WP Table Live Sync22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
ModificadaMedia (6.5)0.59%—Thoughtworks Node-worker-threads-pool11/8/202317/6/2026
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
ModificadaMedia (4.3)0.68%—Wppool WP Dark Mode27/3/202317/6/2026
The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory…
ModificadaMedia (5.4)0.46%—Wppool WP Dark Mode21/2/202317/6/2026
The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack
ModificadaMedia (6.5)0.70%—Pgpool-ii30/1/202317/6/2026
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series,…
ModificadaAlta (8.1)0.54%—Ssharpsmartthreadpool Project Ssharpsmartthreadpool18/1/202317/6/2026
A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPool.cs. The manipulation leads to race condition within a thread. The complexity of an attack is rather high. The exploitability is told to…
ModificadaAlta (8.1)1.2%—Syncpool Project Syncpool8/8/202117/6/2026
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
ModificadaCrítica (9.8)2.8%—Heroku-addonpool Project Heroku-addonpool6/4/202017/6/2026
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
ModificadaMedia (6.1)0.91%—Antoineh Football Pool20/8/201917/6/2026
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
ModificadaCrítica (9.8)2.0%—Mlmsoftwarez ADD Clicking MLM SoftwareMlmsoftwarez Autopool MLM SoftwareMlmsoftwarez Bidding MLM SoftwareMlmsoftwarez Binary MLM Software+624/5/201917/6/2026
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the…