Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.30% | — | Wptravelengine WP Travel Engine | 13/6/2025 | 17/6/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Crítica (9.8) | 0.55% | 💥 PoC | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Privilege Escalation.This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from… | |
| Aplazada | Alta (7.5) | 0.54% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E Commerce LightAI | 9/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Path Traversal.This issue affects Spreadsheet Price Changer for… | |
| Aplazada | Crítica (10) | 0.47% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Code Injection.This issue affects Spreadsheet Price Changer for WooCommerce and WP… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows SQL Injection.This issue affects Spreadsheet Price Changer… | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. | |
| Aplazada | Media (4.3) | 0.25% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+1 | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. | |
| Analizada | Crítica (9.6) | 2.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. | |
| Aplazada | Alta (7.5) | 0.74% | — | Wptravelengine WP Travel EngineAI | 6/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.5.1. | |
| Analizada | Media (5.5) | 0.51% | — | Phpgurukul Local Services Search Engine Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This vulnerability affects unknown code of the file /admin/edit-person-detail.php?editid=2. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Crítica (9.8) | 1.1% | — | Cisco Identity Services Engine | 4/6/2025 | 17/6/2026 | A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt… | |
| Analizada | Alta (7.2) | 0.51% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 4/6/2025 | 17/6/2026 | A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An… | |
| Aplazada | Alta (8.7) | 0.32% | — | 3DS 3dexperienceAI3DS Service Process EngineerAI | 30/5/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Alta (8.3) | 1.5% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. | |
| Analizada | Alta (8.3) | 37% | — | Zohocorp Manageengine Adaudit Plus | 23/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. | |
| Analizada | Alta (8.3) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. | |
| Analizada | Alta (8.3) | 5.9% | — | Zohocorp Manageengine Adaudit Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. | |
| Analizada | Media (6.5) | 1.6% | — | Zohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 22/5/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | |
| Analizada | Media (4.8) | 0.26% | — | Cisco Identity Services Engine | 21/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Analizada | Alta (8.6) | 0.70% | — | Cisco Identity Services Engine | 21/5/2025 | 17/6/2026 | A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this… | |
| Analizada | Alta (7.2) | 2.2% | — | Orangelab Imagemagick Engine | 15/5/2025 | 17/6/2026 | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution. | |
| Modificada | Media (6.8) | 0.55% | — | Wpengine Genesis Blocks | 15/5/2025 | 17/6/2026 | The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks. | |
| Analizada | Media (4.8) | 0.31% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 15/5/2025 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |