Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.30% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Truelysell CoreAI | 14/2/2026 | 17/6/2026 | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges,… | |
| Aplazada | Media (6.5) | 0.20% | — | Farmfe CoreAI | 12/2/2026 | 17/6/2026 | npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket client. This allows attackers to surveil developers running Farm who visit their webpage and steal source code that is leaked by the WebSocket… | |
| Aplazada | Alta (8.8) | 0.34% | — | Videospirecore Theme PluginAI | 11/2/2026 | 17/6/2026 | The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated… | |
| Analizada | Baja (3.7) | 0.43% | — | Langchain Core | 10/2/2026 | 17/6/2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery… | |
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no… | |
| Analizada | Media (4.3) | 0.17% | — | SAP S4core | 10/2/2026 | 17/6/2026 | SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted. | |
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the… | |
| Aplazada | Media (6.7) | 0.44% | — | Coreftp Core FTP LiteAI | 7/2/2026 | 17/6/2026 | Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction. | |
| Aplazada | Media (6.7) | 0.42% | — | Coreftp Core FTP LEAI | 7/2/2026 | 17/6/2026 | Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the application to become unresponsive and… | |
| Aplazada | Alta (7.5) | 0.70% | — | Chetans9 Core-php-admin-panelAI | 3/2/2026 | 17/6/2026 | chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_validate.php. The application sends an HTTP redirect via header(Location:login.php) when a user is not authenticated but fails to call exit() afterward. This allows remote unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.42% | — | Llamaindex Llama Index CoreAI | 2/2/2026 | 17/6/2026 | The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (`num_files_limit`) is applied after all files in a directory are loaded into memory. This can lead… | |
| Aplazada | Media (5.1) | 0.46% | — | Orchard CoreAI | 30/1/2026 | 17/6/2026 | Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers. | |
| Analizada | Crítica (10) | 0.33% | — | Azerothcore | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib modules). This vulnerability is associated with program files inflate.C. This issue affects azerothcore-wotlk: through v4.0.0. | |
| Aplazada | Alta (7.5) | 0.35% | — | Devsblink Edublink CoreAIPHPAI | 23/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local File Inclusion.This issue affects EduBlink Core: from n/a through <= 2.0.7. | |
| Aplazada | Alta (7.5) | 0.45% | — | Elated-themes Laurent CoreAI | 23/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core laurent-core allows PHP Local File Inclusion.This issue affects Laurent Core: from n/a through <= 2.4.1. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Amenotech Workreap CoreAI | 22/1/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This issue affects Workreap Core: from n/a through <= 3.4.1. | |
| Aplazada | Alta (8.1) | 0.47% | — | Webuniuslab Irecco CoreAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab iRecco Core irecco-core allows PHP Local File Inclusion.This issue affects iRecco Core: from n/a through <= 1.3.6. | |
| Aplazada | Alta (7.1) | 0.29% | — | Favethemes Homey CoreAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey Core homey-core allows Reflected XSS.This issue affects Homey Core: from n/a through <= 2.4.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Purethemes Workscout-coreAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affects WorkScout-Core: from n/a through <= 1.7.06. | |
| Aplazada | Alta (8.1) | 0.59% | — | Tangiblewp Listivo CoreAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP Listivo Core listivo-core allows PHP Local File Inclusion.This issue affects Listivo Core: from n/a through <= 2.3.77. | |
| Aplazada | Alta (7.5) | 0.54% | — | Tangiblewp Myhome CoreAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0. | |
| Aplazada | Alta (8.8) | 0.69% | — | Artbees Jupiterx CoreAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1. | |
| Analizada | Crítica (9.8) | 1.6% | 💥 PoC | Docling-core | 22/1/2026 | 17/6/2026 | Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core starting in version 2.21.0 and prior to version 2.48.4, specifically… |