Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.67% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unknown code of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument portraitFile leads to unrestricted upload. The attack… | |
| Analizada | Media (5.3) | 0.39% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This affects an unknown part of the file /admin/sys/user/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.39% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/sys/log/list. The manipulation of the argument logId leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (5.3) | 0.42% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.42% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an unknown function of the file /admin/sys/menu/list. The manipulation of the argument sort/order leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (6.1) | 0.37% | — | UpdraftplusAI | 15/1/2025 | 17/6/2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.72% | — | UpdraftplusAI | 4/1/2025 | 17/6/2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known… | |
| Modificada | Media (6.1) | 0.29% | — | Chatplusjp | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chatplusjp chatplusjp chatplusjp allows Reflected XSS.This issue affects chatplusjp: from n/a through <= 1.02. | |
| Aplazada | Alta (7.5) | 0.45% | — | Ledvance SmartplusAI | 11/10/2024 | 5/7/2026 | LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Modificada | Alta (8.8) | 0.29% | — | Mainwp Updraftplus Extension | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6. | |
| Aplazada | Alta (7.5) | 0.59% | — | Convertplug ConvertplusAI | 16/5/2024 | 17/6/2026 | The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (6.1) | 0.55% | — | Updraftplus All-in-one Security | 7/2/2024 | 17/6/2026 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (5.4) | 0.22% | — | Updraftplus | 7/11/2023 | 17/6/2026 | The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update… | |
| Modificada | Media (6.1) | 0.38% | — | Updraftplus Updraft | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions. | |
| Modificada | Media (6.1) | 1.2% | — | Srbtranslatin Project SrbtranslatinUpdraftplus Wp-optimize | 10/7/2023 | 17/6/2026 | The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability. | |
| Modificada | Media (6.1) | 0.21% | — | Updraftplus | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS). | |
| Modificada | Media (4.8) | 32% | — | Updraftplus All-in-one Security | 10/4/2023 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this… | |
| Modificada | Media (4.9) | 20% | — | Updraftplus All-in-one Security | 10/4/2023 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last… | |
| Modificada | Media (5.3) | 0.66% | — | Updraftplus All-in-one Security | 23/1/2023 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address. | |
| Modificada | Media (5.3) | 0.58% | — | Updraftplus All-in-one Security | 12/12/2022 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, brute force protection, and more). | |
| Modificada | Baja (3.3) | 0.21% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enable attackers with command line access to access the device’s Wi-Fi module. | |
| Modificada | Alta (7.1) | 0.47% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices. | |
| Modificada | Alta (7.5) | 0.62% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface. | |
| Modificada | Alta (7.5) | 1.9% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges. | |
| Modificada | Media (6.3) | 0.21% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration. |