Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 1.5% | — | Zohocorp Manageengine Adselfservice Plus | 3/3/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | |
| Analizada | Media (6.5) | 0.28% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Analizada | Alta (7.5) | 0.50% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (5.4) | 0.24% | — | Novachron Zeitsysteme Gmbh & CO. KG Smart Time PlusAI | 24/2/2025 | 17/6/2026 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint. | |
| Aplazada | Media (6.5) | 0.24% | — | Novachron Zeitsysteme Smart Time PlusAI | 24/2/2025 | 17/6/2026 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Alta (8.9) | 10% | 💥 Exploit | Jsonpath-plusAI | 15/2/2025 | 17/6/2026 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for… | |
| Aplazada | Media (5.9) | 0.24% | — | ZF Roll Stability Support PlusAI | 13/2/2025 | 17/6/2026 | ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment or via pivot from J2497 telematics devices) call diagnostic functions intended for… | |
| Analizada | Alta (8.1) | 0.47% | 💥 PoC | Convertplug Convertplus | 12/2/2025 | 17/6/2026 | The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.3) | 0.13% | — | Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+9 | 6/2/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,… | |
| Analizada | Media (5.3) | 2.8% | 💥 PoC | F5 NginxF5 Nginx PlusDebian Linux | 5/2/2025 | 17/6/2026 | When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets… | |
| Analizada | Alta (7.5) | 0.31% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+165 | 3/2/2025 | 17/6/2026 | Information disclosure while parsing the OCI IE with invalid length. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+123 | 3/2/2025 | 17/6/2026 | Memory corruption while power-up or power-down sequence of the camera sensor. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p Firmware+76 | 3/2/2025 | 17/6/2026 | Memory corruption can occur in the camera when an invalid CID is used. | |
| Analizada | Media (5.4) | 0.31% | — | Wordplus Better Messages | 1/2/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output… | |
| Analizada | Media (5.4) | 0.41% | — | Posimyth THE Plus Addons FOR Elementor | 1/2/2025 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output… | |
| Aplazada | Alta (7.1) | 0.26% | — | Algolplus Advanced Dynamic Pricing FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in algol.plus Advanced Dynamic Pricing for WooCommerce advanced-dynamic-pricing-for-woocommerce allows Reflected XSS.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through <= 4.9.0. | |
| Aplazada | Media (6.5) | 0.32% | — | BYD QIN Plus Dm-iAIBYD Dilink OSAI | 27/1/2025 | 17/6/2026 | Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs. | |
| Aplazada | Media (6.5) | 0.32% | — | Pixocial Technology Beautyplus IOSAI | 27/1/2025 | 17/6/2026 | An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link. | |
| Analizada | Media (5.1) | 0.29% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/sys/admin.html. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.38% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this vulnerability is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument text leads to open redirect.… | |
| Analizada | Media (6.9) | 0.68% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. Affected is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument w/h leads to resource consumption. It is possible… | |
| Analizada | Media (5.3) | 0.55% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue affects some unknown processing of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument name leads to path traversal. The… | |
| Modificada | Media (4.3) | 0.22% | — | G5plus Essential Real Estate | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in g5theme Essential Real Estate essential-real-estate allows Cross Site Request Forgery.This issue affects Essential Real Estate: from n/a through <= 5.1.8. |