Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.30% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… | |
| Aplazada | Alta (8.5) | 0.21% | — | Privateinternetaccess Private Internet AccessAI | 13/1/2026 | 17/6/2026 | Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during… | |
| Aplazada | Media (5.3) | 0.28% | — | Silkentrepreneur WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7. | |
| Aplazada | Alta (7.1) | 0.30% | — | SAP S/4 Hana Private CloudAI | 9/12/2025 | 17/6/2026 | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high… | |
| Aplazada | Alta (8.7) | 0.43% | — | Datamosaix Private CloudAI | 9/12/2025 | 17/6/2026 | A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints. | |
| Aplazada | Media (4.3) | 0.29% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa Eprivacy ConsentAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Media (5.8) | 0.49% | 💥 PoC | PrivatebinAI | 13/11/2025 | 17/6/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselection` is enabled in the configuration, the server trusts the `template` cookie… | |
| Analizada | Media (5.4) | 0.12% | — | Privatebin | 13/11/2025 | 17/6/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename contains HTML is reflected verbatim into the page via the drag-and-drop helper, so any user who drops a crafted file on PrivateBin will execute… | |
| Aplazada | Alta (8.6) | 0.35% | — | Datamosaix Private CloudAI | 11/11/2025 | 17/6/2026 | A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website. | |
| Aplazada | Alta (7.6) | 0.15% | — | Datamosaix Private CloudAI | 11/11/2025 | 17/6/2026 | A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not completed within a 7-day period. | |
| Aplazada | Media (4.3) | 0.22% | — | Michielvaneerd Private Google CalendarsAI | 11/11/2025 | 17/6/2026 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the… | |
| Aplazada | Media (5.8) | 0.29% | — | PrivatebinAI | 28/10/2025 | 17/6/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow persistent HTML injection via the unsanitized attachment filename (attachment_name) when attachments are enabled. An attacker can modify attachment_name before encryption so that, after decryption,… | |
| Aplazada | Alta (7.2) | 0.15% | — | Netknights Gmbh Privacyidea AuthenticatorAI | 27/10/2025 | 17/6/2026 | Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of… | |
| Aplazada | Alta (7.1) | 0.25% | — | Bobbingwide Oik-privacy-policyAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.10. | |
| Aplazada | Alta (8.2) | 0.31% | — | Amenotech Private Limited WpguppyAIAmenotech Private Limited Wpguppy LiteAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.5) | 0.30% | 💥 PoC | Wpexpertdeveloper WP Private Content PlusAI | 13/10/2025 | 17/6/2026 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpexpertdeveloper WP Private Content PlusAI | 12/8/2025 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and… | |
| Aplazada | Alta (7) | 0.17% | — | Imprivata Enterprise Access ManagementAI | 23/7/2025 | 17/6/2026 | A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts.… | |
| Aplazada | Alta (7.8) | 0.33% | — | Private-ipAI | 23/7/2025 | 17/6/2026 | All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package's source code. | |
| Aplazada | Alta (7.5) | 0.62% | — | Lcweb Privatecontent - Mail ActionsAI | 4/7/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File Inclusion. This issue affects PrivateContent - Mail Actions: from n/a through 2.3.2. | |
| Analizada | Alta (7.5) | 0.44% | — | Fabiantodt Private Post Share | 4/7/2025 | 17/6/2026 | The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API. | |
| Analizada | Alta (7.5) | 0.82% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 18/6/2025 | 17/6/2026 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a… | |
| Aplazada | Alta (7.7) | 0.48% | — | HPE Aruba Networking Private 5G CoreAI | 10/6/2025 | 17/6/2026 | A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information. |