Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.67%—Joeybling Bootplus24/1/202517/6/2026
A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unknown code of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument portraitFile leads to unrestricted upload. The attack…
AnalizadaMedia (5.3)0.39%—Joeybling Bootplus24/1/202517/6/2026
A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This affects an unknown part of the file /admin/sys/user/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.39%—Joeybling Bootplus24/1/202517/6/2026
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/sys/log/list. The manipulation of the argument logId leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (5.3)0.42%—Joeybling Bootplus24/1/202517/6/2026
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can be launched…
AnalizadaMedia (5.3)0.42%—Joeybling Bootplus24/1/202517/6/2026
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an unknown function of the file /admin/sys/menu/list. The manipulation of the argument sort/order leads to sql injection. It is possible to launch the attack remotely. The…
AnalizadaMedia (5.4)0.24%—Buddydev Activity Plus Reloaded FOR Buddypress24/1/202517/6/2026
The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to…
AnalizadaCrítica (9.8)1.3%—G5plus Ultimate Bootstrap Elements FOR Elementor24/1/202517/6/2026
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass…
AnalizadaCrítica (9.5)0.35%—Ecovacs Deebot X2 Omni FirmwareEcovacs Deebot X2 Combo FirmwareEcovacs Deebot X2S FirmwareEcovacs Deebot X5 PRO Firmware+1623/1/202517/6/2026
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
AplazadaAlta (7.1)0.25%—Jmraya Legal PlusAI23/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jmraya Legal + legal-plus allows Reflected XSS.This issue affects Legal +: from n/a through <= 1.0.
AnalizadaMedia (5.8)3.0%—Ecovacs Goat G1-2000 FirmwareEcovacs Goat G1 FirmwareEcovacs Goat G1-800 FirmwareEcovacs Gx-600 Firmware+823/1/202517/6/2026
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
AplazadaAlta (8.5)0.47%—Keighl Menus PlusAI22/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in keighl Menus Plus+ menus-plus allows SQL Injection.This issue affects Menus Plus+: from n/a through <= 1.9.6.
AplazadaAlta (7.1)0.37%—Tahminajannat Redirection PlusAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tahminajannat REDIRECTION PLUS redirection-plus allows Reflected XSS.This issue affects REDIRECTION PLUS: from n/a through <= 2.0.0.
AplazadaAlta (8.6)0.44%—CP Plus RouterAI20/1/202517/6/2026
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the…
AplazadaAlta (7.1)0.16%—Cybio Floatbox PlusAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cybio Floatbox Plus floatbox-plus allows Stored XSS.This issue affects Floatbox Plus: from n/a through <= 1.4.4.
AplazadaMedia (5.3)0.59%—Sanjay Prasad LoginplusAI16/1/202517/6/2026
Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Loginplus: from n/a through <= 1.2.
AplazadaMedia (6.1)0.37%—UpdraftplusAI15/1/202517/6/2026
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AnalizadaMedia (5.9)0.37%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.
AnalizadaAlta (7.4)0.31%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.
AnalizadaMedia (5.9)0.46%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.
AnalizadaMedia (5.9)0.46%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.
AnalizadaAlta (7.8)0.13%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1246/1/202517/6/2026
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
AnalizadaAlta (7.8)0.15%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm4490 Firmware+176/1/202517/6/2026
Memory corruption while processing IPA statistics, when there are no active clients registered.
AplazadaAlta (8.8)0.72%—UpdraftplusAI4/1/202517/6/2026
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known…
AplazadaBaja (3.3)0.17%—Shonen Jump PlusAI17/12/202417/6/2026
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
AplazadaAlta (7.1)0.20%—Crudlab Google Plus ButtonAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab CRUDLab Google Plus Button crudlab-google-plus allows Stored XSS.This issue affects CRUDLab Google Plus Button: from n/a through <= 1.0.2.