Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.80% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Autoprimary SOA Queries | |
| Analizada | Alta (8.6) | 0.54% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Names During AXFR | |
| Analizada | Media (4.8) | 0.19% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Incorrect Behaviour of Views with TCP PROXY Requests | |
| Pendiente de análisis | Media (6) | 0.26% | — | Openthread Authors OpenthreadAI | 13/5/2026 | 17/6/2026 | Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on the adjacent IPv4 network to inject corrupted IPv6 packets into the Thread mesh or bypass security checks via crafted IPv4 packets with options. | |
| Analizada | Media (6.5) | 0.39% | — | Jenkins Matrix Authorization Strategy | 29/4/2026 | 17/6/2026 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to… | |
| Analizada | Media (4.9) | 0.81% | — | Powerdns Authoritative | 22/4/2026 | 17/6/2026 | An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend. | |
| Analizada | Alta (7.5) | 0.73% | — | Powerdns Authoritative | 22/4/2026 | 17/6/2026 | A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it. | |
| Analizada | Media (6.5) | 0.46% | — | Powerdns Authoritative | 22/4/2026 | 17/6/2026 | Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees. | |
| Analizada | Crítica (9.8) | 0.59% | — | Powerdns Authoritative | 22/4/2026 | 17/6/2026 | An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it. | |
| Analizada | Alta (7.5) | 1.1% | — | Powerdns AuthoritativePowerdns DnsdistPowerdns Recursor | 22/4/2026 | 17/6/2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. | |
| Analizada | Alta (7.5) | 1.1% | — | Powerdns AuthoritativePowerdns DnsdistPowerdns Recursor | 22/4/2026 | 17/6/2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. | |
| Analizada | Media (5.5) | 0.11% | — | Linuxfoundation Sigstore Timestamp Authority | 15/4/2026 | 17/6/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert… | |
| Aplazada | Media (5.3) | 0.31% | — | Paul Bearne Author Avatars List BlockAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through <= 2.1.25. | |
| Aplazada | Alta (7.5) | 0.29% | — | Publishpress AuthorsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1. | |
| Aplazada | Alta (7.5) | 0.26% | — | Themeplugs AuthorsyAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Authorsy: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.3) | 0.19% | — | Publishpress AuthorsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1. | |
| Aplazada | Media (6.4) | 0.16% | — | Easy Author ImageAI | 19/2/2026 | 17/6/2026 | The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_url' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.1) | 0.22% | — | Personal-authors-categoryAI | 14/2/2026 | 17/6/2026 | The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Crítica (9.8) | 2.5% | 💥 PoC | Microsoft Azure Conversation Authoring Client Library | 10/2/2026 | 17/6/2026 | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.4) | 0.27% | — | Themeruby Multi AuthorsAI | 24/1/2026 | 17/6/2026 | The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' shortcode attributes in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.44% | — | Cardpaysolutions Payment Gateway Authorize NET CIM FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce authnet-cim-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Authorize.Net CIM for WooCommerce: from n/a through <= 2.1.2. | |
| Analizada | Media (5.3) | 0.22% | — | Quest Kace Desktop Authority | 12/1/2026 | 17/6/2026 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication | |
| Aplazada | Alta (7.1) | 0.22% | — | Osuthorpe Easy SocialAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3. | |
| Analizada | Alta (7.5) | 0.44% | — | Linuxfoundation Sigstore Timestamp Authority | 4/12/2025 | 17/6/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also… | |
| Aplazada | Media (6.1) | 0.12% | — | AuthorsureAI | 21/11/2025 | 17/6/2026 | The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the 'authorsure' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… |