Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.58%—Funadmin25/10/202417/6/2026
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
AnalizadaAlta (7.2)0.56%—Funadmin25/10/202417/6/2026
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
AplazadaMedia (6.4)0.36%—WpadminifyAI24/10/202417/6/2026
The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaAlta (7.2)0.50%—Funadmin21/10/202417/6/2026
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
AnalizadaAlta (8.8)1.1%—Wellchoose Administrative Management System21/10/202417/6/2026
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
AnalizadaAlta (8.8)0.60%—Wellchoose Administrative Management System21/10/202417/6/2026
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.
AnalizadaAlta (7.5)0.72%—Wellchoose Administrative Management System21/10/202417/6/2026
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.
AplazadaMedia (6.5)0.26%—Wpseek Admin Management XtendedAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Stored XSS.This issue affects Admin Management Xtended : from n/a through <= 2.4.6.
AnalizadaAlta (7.3)0.41%—Ari-soft ARI Adminer16/10/202417/6/2026
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and perform a wide variety of unauthorized…
AnalizadaMedia (6.3)1.7%💥 PoCNetadmin IAM4/10/202417/6/2026
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument username leads to…
AplazadaMedia (4.8)0.37%—Metronic Admin Dashboard TemplateAI30/9/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AnalizadaMedia (5.3)0.55%—Skyselang Yyladmin27/9/202417/6/2026
A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (5.3)0.39%—Kvf-admin Project Kvf-admin27/9/202417/6/2026
A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component XML File Handler. The manipulation of the argument upfile leads…
AnalizadaMedia (5.1)0.58%—Kvf-admin Project Kvf-admin27/9/202417/6/2026
A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely.…
AnalizadaMedia (5.1)0.45%—Funnyzpc Mee-admin27/9/202417/6/2026
A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of the component User Center. The manipulation of the argument User Nickname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (6.5)9.7%💥 ExploitPgadmin 423/9/202417/6/2026
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
ModificadaMedia (6.1)0.35%—Iredmail Iredadmin23/9/202417/6/2026
iRedAdmin before 2.6 allows XSS, e.g., via order_name.
AplazadaCrítica (9.9)0.48%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI17/9/202417/6/2026
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
AnalizadaMedia (6.5)0.20%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
AnalizadaMedia (4.3)0.34%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
AnalizadaMedia (6.5)0.73%—Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+611/9/202417/6/2026
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for…
ModificadaCrítica (9.8)0.50%—Eladmin10/9/202417/6/2026
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
ModificadaMedia (4.8)0.50%—Eladmin10/9/202417/6/2026
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
AplazadaAlta (8.8)0.38%—Visual Planning Admin CenterAI3/9/202417/6/2026
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain different types of configured credentials and…
ModificadaAlta (7.5)67%—OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+153/9/202417/6/2026
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.…
Orbitaley — Vulnerabilidades