Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4531 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Autogen Headers MenuAI | 9/1/2026 | 17/6/2026 | The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' parameter of the 'autogen_menu' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.42% | — | Redhat Ansible Automation PlatformAI | 8/1/2026 | 17/6/2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Themesuite Automotive ListingsAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through <= 18.6. | |
| Modificada | Crítica (9.6) | 1.3% | 💥 PoC | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 6/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Analizada | Media (5.5) | 0.13% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+171 | 7/1/2026 | 7/10/2026 | Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+200 | 7/1/2026 | 7/10/2026 | Memory corruption while processing identity credential operations in the trusted application. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Sa8145p FirmwareQualcomm Sa8150p FirmwareQualcomm Sa8155p FirmwareQualcomm Sa8195p Firmware+109 | 7/1/2026 | 7/10/2026 | Memory corruption while processing a secure logging command in the trusted application. | |
| Analizada | Alta (8.4) | 0.13% | — | Qualcomm Wcd9385 FirmwareQualcomm Wcd9390 FirmwareQualcomm Wcd9395 FirmwareQualcomm Wcn3950 Firmware+101 | 7/1/2026 | 7/10/2026 | Cryptographic issue may occur while encrypting license data. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+181 | 7/1/2026 | 7/10/2026 | Memory corruption while deinitializing a HDCP session. | |
| Analizada | Media (6.6) | 0.12% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+235 | 7/1/2026 | 7/10/2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | |
| Analizada | Media (6.1) | 0.13% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+295 | 7/1/2026 | 7/10/2026 | Information disclosure while processing a firmware event. | |
| Analizada | Media (5.5) | 0.12% | — | Qualcomm Qca6678aq FirmwareQualcomm Qca6688aq FirmwareQualcomm Qca6696 FirmwareQualcomm Qca6698aq Firmware+219 | 7/1/2026 | 7/10/2026 | Transient DOS while parsing video packets received from the video firmware. | |
| Aplazada | Media (5.4) | 0.12% | — | Automattic WP JOB ManagerAI | 5/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n/a through 2.0.0. | |
| Aplazada | Media (5.3) | 0.23% | — | Wawp Automation-web-platformAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Information Technology Wawp automation-web-platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wawp: from n/a through <= 4.4. | |
| Aplazada | Media (6.5) | 0.15% | — | Wpautolistings Auto ListingsAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto Listings auto-listings allows Stored XSS.This issue affects Auto Listings: from n/a through <= 2.7.1. | |
| Aplazada | Baja (3.8) | 0.37% | 💥 PoC | Automattic Crowdsignal FormsAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2. | |
| Analizada | Media (4.8) | 0.25% | — | Dronecode PX4 Drone Autopilot | 28/12/2025 | 7/10/2026 | A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer overflow. The attack is only possible with… | |
| Aplazada | Alta (7.6) | 0.27% | — | AutomatorwpAI | 23/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4. | |
| Aplazada | Alta (7.3) | 0.25% | — | Inductiveautomation IgnitionAI | 18/12/2025 | 28/8/2026 | Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file… | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+107 | 18/12/2025 | 17/6/2026 | Memory corruption while handling IOCTL calls to set mode. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+209 | 18/12/2025 | 17/6/2026 | Memory corruption while processing MFC channel configuration during music playback. | |
| Analizada | Media (6.7) | 0.09% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+114 | 18/12/2025 | 17/6/2026 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+174 | 18/12/2025 | 30/9/2026 | Memory corruption while routing GPR packets between user and root when handling large data packet. | |
| Aplazada | Media (4.3) | 0.30% | — | Cm-wp Auto Featured ImageAI | 16/12/2025 | 7/10/2026 | The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Alta (7.8) | 0.26% | — | Autodesk Shared Components | 15/12/2025 | 7/10/2026 | A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |