Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.62% | — | Dynamiapps Frontend Admin | 21/12/2024 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.66% | — | Directadmin Evolution SkinAI | 20/12/2024 | 17/6/2026 | Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code. If an admin views the ticket, the script might perform actions with their privileges, including command execution. This issue has been… | |
| Aplazada | Media (5) | 0.42% | — | PhpldapadminAI | 19/12/2024 | 17/6/2026 | phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this… | |
| Aplazada | Baja (2.1) | 0.50% | — | PhpldapadminAI | 19/12/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However,… | |
| Aplazada | Media (4.8) | 0.34% | — | MY WP Customize Admin FrontendAI | 17/12/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page. | |
| Aplazada | Media (6.3) | 0.44% | — | Funnyzpc Mee-adminAI | 16/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable response discrepancy. The attack can be initiated remotely. The complexity of an… | |
| Aplazada | Alta (7.1) | 0.20% | — | Phuc Pham Multiple Admin EmailsAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Phuc Pham Multiple Admin Emails multiple-admin-emails allows Cross Site Request Forgery.This issue affects Multiple Admin Emails: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.77% | — | Chris Gardenberg Eduadmin BookingAI | 16/12/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmin Booking eduadmin-booking allows PHP Local File Inclusion.This issue affects EduAdmin Booking: from n/a through <= 5.2.0. | |
| Analizada | Alta (8.1) | 0.56% | — | Dynamiapps Frontend Admin | 14/12/2024 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for unauthenticated attackers to create new… | |
| Analizada | Media (6.1) | 0.36% | — | Dynamiapps Frontend Admin | 14/12/2024 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.8) | 0.29% | — | Eewee Admin CustomAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in eewee eewee admin custom eewee-admincustom allows Privilege Escalation.This issue affects eewee admin custom: from n/a through <= 1.8.2.4. | |
| Aplazada | Media (5.3) | 0.63% | — | Michal Novak Secure Admin IPAI | 13/12/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0. | |
| Aplazada | Media (4.7) | 0.48% | — | Numerix License Server Administration SystemAI | 11/12/2024 | 17/6/2026 | Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST… | |
| Modificada | Baja (3.4) | 1.3% | — | Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+7 | 11/12/2024 | 17/6/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either… | |
| Aplazada | Alta (7.2) | 0.27% | — | SAP Netweaver AdministratorAI | 10/12/2024 | 17/6/2026 | SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and… | |
| Analizada | Alta (8.1) | 0.36% | — | Dell Openmanage Server Administrator | 9/12/2024 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or… | |
| Analizada | Alta (8.8) | 0.34% | — | Dell Openmanage Server Administrator | 9/12/2024 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges. | |
| Aplazada | Media (4.3) | 0.37% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.31. | |
| Analizada | Media (5.3) | 0.39% | — | Code-projects Admin Dashboard | 9/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.3) | 0.55% | — | Andy Moyle Church AdminAI | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Church Admin: from n/a through <= 5.0.8. | |
| Aplazada | Media (5.3) | 0.53% | — | Ibexa Admin UI BundleAI | 29/11/2024 | 17/6/2026 | Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected… | |
| Aplazada | Media (4.8) | 0.38% | — | WP Admin UI CustomizeAI | 26/11/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen. | |
| Analizada | Alta (7.3) | 0.41% | — | Radmin Advanced IP Scanner | 22/11/2024 | 17/6/2026 | Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Aplazada | Media (4.3) | 0.19% | — | Themeisle Disable Admin NoticesAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Disable Admin Notices individually disable-admin-notices allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Sroyalty Admin SMS AlertAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sroyalty Admin SMS Alert admin-sms-alert allows Stored XSS.This issue affects Admin SMS Alert: from n/a through <= 1.1.0. |