Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
293.879 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.37% | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | |
| Recibida | Alta (8.1) | 0.21% | — | Zephyrproject ZephyrAI | 7/10/2026 | 7/10/2026 | ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter… | |
| Recibida | Alta (8.8) | 0.31% | — | Zephyrproject ZephyrAI | 7/10/2026 | 7/10/2026 | The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out,… | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | — | Ordasoft Simple MembershipAI | 7/10/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter,… | |
| Pendiente de análisis | Media (6.9) | 0.24% | — | Ordasoft Touch SliderAI | 7/10/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a… | |
| Pendiente de análisis | Crítica (9.4) | 0.36% | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. | |
| Pendiente de análisis | Media (4.8) | 0.34% | — | Veeam Backup Enterprise ManagerAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Aplazada | Media (4.1) | 0.18% | — | Blubrry PowerpressAI | 7/10/2026 | 7/10/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services. | |
| Aplazada | Media (4.3) | 0.18% | — | Userprivatefiles User Private FilesAI | 7/10/2026 | 7/10/2026 | The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators. | |
| Aplazada | Alta (8.8) | 0.38% | — | String LocatorAI | 7/10/2026 | 7/10/2026 | The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a… | |
| Aplazada | Media (5.4) | 0.16% | — | MetformAI | 7/10/2026 | 7/10/2026 | The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | |
| Aplazada | Media (5.3) | 0.23% | — | Themewinter WpcafeAI | 7/10/2026 | 7/10/2026 | The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | |
| Aplazada | Media (5.3) | 0.19% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay). | |
| Aplazada | Alta (7.1) | 0.16% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting. | |
| Aplazada | Baja (2.7) | 0.17% | — | CP Media PlayerAI | 7/10/2026 | 7/10/2026 | The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that… | |
| Aplazada | Alta (7.2) | 0.37% | — | Wow-company WP CoderAI | 7/10/2026 | 7/10/2026 | The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site. | |
| Aplazada | Media (6.8) | 0.23% | — | Wpmart Animated Number CountersAI | 7/10/2026 | 7/10/2026 | The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data… | |
| Aplazada | Media (6.8) | 0.24% | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an… | |
| Aplazada | Media (6.8) | 0.24% | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the… | |
| Aplazada | Media (4.3) | 0.13% | — | Yaad Sarig Payment Gateway FOR WCAI | 7/10/2026 | 7/10/2026 | The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers. | |
| Aplazada | Media (4.3) | 0.13% | — | Buffercode Frontend DashboardAI | 7/10/2026 | 7/10/2026 | The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields. | |
| Aplazada | Media (6.5) | 0.14% | — | Geliver Akillikargo PazaryeriAI | 7/10/2026 | 7/10/2026 | The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key… | |
| Aplazada | Media (5.9) | 0.14% | — | Integration FOR Epos NOW AND WoocommerceAI | 7/10/2026 | 7/10/2026 | The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails… |