Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),… | |
| Aplazada | Alta (7) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP… | |
| Analizada | Alta (8.8) | 0.18% | — | Rockwellautomation Rslogix 5Rockwellautomation Rslogix 500Rockwellautomation Rslogix Micro DeveloperRockwellautomation Rslogix Micro Starter Lite | 14/10/2024 | 17/6/2026 | VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables users to prepare a project file with an… | |
| Aplazada | Media (5.9) | 0.27% | — | Brainstormforce Starter TemplatesAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through <= 4.4.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Spicethemes Spice Starter SitesAI | 1/10/2024 | 17/6/2026 | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to import demo content. | |
| Aplazada | Media (5.3) | 0.36% | — | Stylemixthemes Masterstudy LMS StarterAI | 25/9/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8. | |
| Modificada | Media (6.1) | 0.27% | — | Spicethemes Spice Starter Sites | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This issue affects Spice Starter Sites: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.5) | 0.25% | — | Visualcomposer Visual Composer StarterAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visual Composer Visual Composer Starter allows Stored XSS.This issue affects Visual Composer Starter: from n/a through 3.3. | |
| Aplazada | Media (6.4) | 0.33% | — | Athemes Starter SitesAI | 27/7/2024 | 17/6/2026 | The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Alta (7) | 0.21% | — | Siemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAISiemens Simatic WinccAI+7 | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2), SIMATIC STEP 7 V16 (All versions < V16 Update 7), SIMATIC STEP 7 V17 (All versions < V17 Update 7), SIMATIC… | |
| Modificada | Media (6.5) | 0.40% | — | Brainstormforce Starter Templates | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5. | |
| Modificada | Media (6.3) | 0.65% | — | Nasirkhan Laravel Starter | 17/6/2024 | 17/6/2026 | A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to observable response discrepancy. The attack… | |
| Aplazada | Media (6.4) | 0.45% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.29% | — | CmsaassstarterAITailwindAISupabaseAISveltekitAI | 14/5/2024 | 17/6/2026 | CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch… | |
| Aplazada | Media (4.3) | 0.57% | — | Starter TemplatesAI | 14/5/2024 | 17/6/2026 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web… | |
| Aplazada | Alta (7.1) | 0.32% | — | Brainstormforce Starter Templates Elementor Wordpress Beaver Builder TemplatesAIBrainstormforce Premium Starter TemplatesAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates:… | |
| Analizada | Alta (8.1) | 1.0% | — | Fullstackhero .net 9 Starter KIT | 29/2/2024 | 17/6/2026 | A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request. | |
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Starter Templates | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4. | |
| Modificada | Crítica (9.8) | 1.1% | — | Acyba Acymailing Starter | 17/8/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution. | |
| Modificada | Alta (8.8) | 0.26% | — | Brainstormforce Starter Templates | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | |
| Modificada | Alta (8.8) | 0.92% | — | Kadencewp Starter Templates | 9/1/2023 | 17/6/2026 | The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Media (6.1) | 0.53% | — | Starter-public-edition-4 Project Starter-public-edition-4 | 17/12/2022 | 17/6/2026 | A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is… | |
| Modificada | Media (5.4) | 0.68% | — | Getkirby Starterkit | 18/8/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field. | |
| Modificada | Media (5.4) | 0.60% | — | Brainstormforce Starter Templates | 17/11/2021 | 17/6/2026 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious… | |
| Modificada | Alta (7.5) | 0.98% | — | Phoenixcontact Plcnext Technology Starterkit FirmwarePhoenixcontact AXC F 2152 Starterkit FirmwarePhoenixcontact RFC 4072s FirmwarePhoenixcontact AXC F 3152 Firmware+2 | 27/9/2021 | 17/6/2026 | Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests. |