Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4531 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.13%—Flashyapp WP Flashy Marketing AutomationAI9/12/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Flashyapp WP Flashy Marketing Automation wp-flashy-marketing-automation allows Cross Site Request Forgery.This issue affects WP Flashy Marketing Automation: from n/a through <= 2.0.8.
AplazadaMedia (4.3)0.13%—Valerio Monti Auto ALT TextAI9/12/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Valerio Monti Auto Alt Text auto-alt-text allows Cross Site Request Forgery.This issue affects Auto Alt Text: from n/a through <= 2.5.2.
AplazadaMedia (5.3)0.32%—Talent Software E-bap AutomationAI9/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS). This issue affects e-BAP Automation: from 1.8.96 before v.41815.
AplazadaAlta (8.8)0.52%—Auto ThumbnailerAI5/12/202517/6/2026
The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the…
AplazadaMedia (6.4)0.29%💥 PoCAutoptimizeAI3/12/202517/6/2026
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it…
AnalizadaCrítica (9.1)0.41%—Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware2/12/202525/9/2026
Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.
AnalizadaMedia (4)0.07%—Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware2/12/202525/9/2026
Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.
AnalizadaCrítica (9.8)0.46%—Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware2/12/202525/9/2026
Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.
AplazadaAlta (8.7)0.33%—Carrier Zone ControllerAIAutomatedlogic Zone ControllerAI27/11/202517/6/2026
A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed.
AplazadaAlta (8.8)0.34%—Carrier I-vu Gen5 RouterAIAutomatedlogic I-vu Gen5 RouterAI27/11/202517/6/2026
—
AplazadaMedia (6.9)0.31%—Carrier I-vuAIAutomatedlogic WebctrlAI27/11/202517/6/2026
The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser .
AplazadaCrítica (9.2)0.33%—Carrier I-vuAIAutomatedlogic WebctrlAI27/11/202517/6/2026
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.
AplazadaMedia (5.3)0.27%—Autochat Automatic ConversationAI25/11/202517/6/2026
The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconnect…
AplazadaMedia (4.3)0.26%—Uncannyowl Uncanny AutomatorAI21/11/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaMedia (5.4)0.12%—Carrier I-vuAIAutomatedlogic WebctrlAI19/11/202517/6/2026
Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized.
AplazadaAlta (8.6)0.16%—Carrier I-vuAIAutomatedlogic WebctrlAI19/11/202517/6/2026
Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions.
AplazadaMedia (6.1)0.25%—WP Twitter Auto PublishAI18/11/202517/6/2026
The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaAlta (7.1)0.16%—Rockwellautomation Arena14/11/20257/10/2026
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a…
AplazadaAlta (8.1)0.37%—Optimus Brokerage AutomationAI14/11/20257/10/2026
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects…
AplazadaMedia (6.5)0.13%—Ramon Fincken Auto-prune-postsAI13/11/20257/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through <= 3.0.0.
AplazadaMedia (6.9)0.58%—AutomgenAI12/11/202516/6/2026
AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through…
AnalizadaAlta (7.8)0.16%—Autodesk 3DS MAX12/11/202517/6/2026
A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.17%—Autodesk 3DS MAX12/11/202517/6/2026
A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.